C&CMembers
C&C

Emotet C2 Hides Behind WordPress Paths on Aged Compromised Domains

Two compromised websites — a Turkish-language platform and a social media aggregator — are serving as active Emotet command-and-control relay nodes, with their WordPress admin and content directories repurposed as beaconing endpoints. The cluster pairs aged domains with registrar diversification, short-lived certificate rotation, and a near-invisible Russian-hosted IP to fragment the cross-indicator footprint defenders rely on for blocking.

Jun 14, 2026, 22:59 (UTC+9)Last seenJun 15, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC10

Two compromised websites — one a Turkish-language platform, the other a social media aggregator — are currently serving as active command-and-control relay nodes for an Emotet campaign cluster, with their WordPress administrative and content directories repurposed as beaconing endpoints. The infrastructure fingerprint CTX Team has documented is precise: dotasarim.com/wp-admin/Dyz and socialplaymedia.com/wp-content/Czj function as the actual C2 URLs, their paths indistinguishable at a glance…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence