
Ludashi PUA Pivots to Cloud-Fronted C2 via Tencent API Gateway
The Ludashi PUA campaign has executed a complete infrastructure rotation, retiring all prior C2 endpoints and replacing them with two new operator-controlled apex domains. The most significant new element is a cloud-fronting technique routing C2 traffic through Tencent Cloud API Gateway, making malicious beacons indistinguishable from legitimate cloud service calls at the TLS layer.
Since CTX Team's earlier coverage of the Ludashi PUA campaign, the observable infrastructure has undergone a complete turnover: twelve new IP addresses, six new domains, and seven new URLs have entered the active indicator set, while every previously tracked file has rotated out. The payload layer is quiet — zero new binaries — but the network layer tells a story of deliberate, operationally sophisticated infrastructure replacement.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read