C&CMembers
C&C

Trojan.Jumper Builds Five-Tier C2 Across 15 Domains and 9 ASNs

The Trojan.Jumper operator has expanded from a single-stage VPN-lure implant into a multi-tier command-and-control architecture spanning 15 domains, nine autonomous systems, and five distinct certificate-issuer clusters provisioned within a 45-day window. A newly introduced Bright Data-signed .NET stealer adds credential harvesting to the campaign's existing foothold capability. The infrastructure build-out — including a DGA-backed domain reserve of roughly 40 algorithmically named names and a freshly stood-up Webzilla relay node in the Netherlands — signals deliberate operational scaling rather than routine maintenance.

May 27, 2026, 13:52 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamIOC32MITRE18

Fifteen new domains. Nine IP addresses spanning six autonomous systems across four continents. Five distinct certificate-issuer fingerprints provisioned within a 45-day window. Since CTX Team's earlier coverage of the Trojan.Jumper campaign, the operator has not merely maintained an existing footprint — they have constructed a layered, multi-tier command-and-control architecture that reveals a level of infrastructure investment inconsistent with opportunistic or low-sophistication adversaries.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence