
Nine No-IP Subdomains, One Account: A .NET Trojan C2 Still Active in 2026
A single No-IP DDNS account holding nine sequentially numbered subdomains — each with 60-second TTL records pointing to European residential IPs — has kept a paired .NET trojan toolkit operational for more than a decade. The infrastructure scores 0/91 on VirusTotal while the payloads compiled in December 2013 remain in circulation as of mid-2026.
A single No-IP dynamic DNS account holds nine sequentially enumerated subdomains — incorrect.no-ip.biz through 8incorrect.no-ip.biz — each configured with 60-second TTL A records pointing to European residential IP addresses, each sharing the same nameserver cluster (NF1 through NF5.NO-IP.COM), and each ready to absorb C2 traffic the moment any sibling is blocked or sinkholed.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read