C&CMembers
C&C

Ludashi PUA Pivots to Cloud-Fronted C2 via Tencent API Gateway

The Ludashi PUA campaign has executed a complete infrastructure rotation, retiring all prior C2 endpoints and replacing them with two new operator-controlled apex domains. The most significant new element is a cloud-fronting technique routing C2 traffic through Tencent Cloud API Gateway, making malicious beacons indistinguishable from legitimate cloud service calls at the TLS layer.

May 28, 2026, 06:11 (UTC+9)Last seenMay 28, 2026Severity100ByCTX TeamActorTA551ShathakIOC44MITRE12

Since CTX Team's earlier coverage of the Ludashi PUA campaign, the observable infrastructure has undergone a complete turnover: twelve new IP addresses, six new domains, and seven new URLs have entered the active indicator set, while every previously tracked file has rotated out. The payload layer is quiet — zero new binaries — but the network layer tells a story of deliberate, operationally sophisticated infrastructure replacement.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence