
C2 Cluster Adds 9 IPs, 20 Domains — Just 5 New Files
Fresh tracking of a trojanized VPN and proxy installer campaign shows the hosting layer expanding aggressively while the malware itself stays untouched. New IPs and domains slot directly into existing certificate and ASN fingerprints spanning Bytedance, Zenlayer, and Alibaba-linked infrastructure.
Nine new IP addresses and twenty new domains have surfaced around a C2-server cluster CTX Team has been tracking since earlier coverage of a campaign built on trojanized VPN and proxy installers ("Two Vendor Signatures, One Stealer"). Only five new files joined the set in the same window. That lopsided ratio is itself the story: the operators are not retooling their malware, they are aggressively provisioning and rotating the network fabric that fronts it.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read