
Cridex C2 Pool Spans Seven Nodes Across Four Continents on One Encoded Path
A Cridex banking trojan payload first compiled in 2012 is still generating active threat-feed hits in 2025–2026, its command-and-control layer deliberately spread across at least seven nodes in Indonesia, Brazil, Thailand, and Mexico. Every node shares a single hardcoded encoded URI path — and nothing else — making network-layer blocking of any one node ineffective against the rest.
At least seven command-and-control nodes spread across Indonesia, Brazil, Thailand, Mexico, and three additional unattributed locations are currently bound by a single hardcoded encoded URI path — /VJuPpCAAA/Vxi22CAAA/AHYe — embedded in a Cridex banking trojan payload that first surfaced in October 2012 and continues to generate active threat-feed hits.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read