
Trojan.Jumper Builds Five-Tier C2 Across 15 Domains and 9 ASNs
The Trojan.Jumper operator has expanded from a single-stage VPN-lure implant into a multi-tier command-and-control architecture spanning 15 domains, nine autonomous systems, and five distinct certificate-issuer clusters provisioned within a 45-day window. A newly introduced Bright Data-signed .NET stealer adds credential harvesting to the campaign's existing foothold capability. The infrastructure build-out — including a DGA-backed domain reserve of roughly 40 algorithmically named names and a freshly stood-up Webzilla relay node in the Netherlands — signals deliberate operational scaling rather than routine maintenance.
Fifteen new domains. Nine IP addresses spanning six autonomous systems across four continents. Five distinct certificate-issuer fingerprints provisioned within a 45-day window. Since CTX Team's earlier coverage of the Trojan.Jumper campaign, the operator has not merely maintained an existing footprint — they have constructed a layered, multi-tier command-and-control architecture that reveals a level of infrastructure investment inconsistent with opportunistic or low-sophistication adversaries.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read