C&CMembers
C&C

Nine No-IP Subdomains, One Account: A .NET Trojan C2 Still Active in 2026

A single No-IP DDNS account holding nine sequentially numbered subdomains — each with 60-second TTL records pointing to European residential IPs — has kept a paired .NET trojan toolkit operational for more than a decade. The infrastructure scores 0/91 on VirusTotal while the payloads compiled in December 2013 remain in circulation as of mid-2026.

Jun 20, 2026, 08:28 (UTC+9)Last seenJun 20, 2026Severity100ByCTX TeamIOC14MITRE37RegionsFR

A single No-IP dynamic DNS account holds nine sequentially enumerated subdomains — incorrect.no-ip.biz through 8incorrect.no-ip.biz — each configured with 60-second TTL A records pointing to European residential IP addresses, each sharing the same nameserver cluster (NF1 through NF5.NO-IP.COM), and each ready to absorb C2 traffic the moment any sibling is blocked or sinkholed.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence