C&CMembers
C&C

Cridex C2 Pool Spans Seven Nodes Across Four Continents on One Encoded Path

A Cridex banking trojan payload first compiled in 2012 is still generating active threat-feed hits in 2025–2026, its command-and-control layer deliberately spread across at least seven nodes in Indonesia, Brazil, Thailand, and Mexico. Every node shares a single hardcoded encoded URI path — and nothing else — making network-layer blocking of any one node ineffective against the rest.

Jun 28, 2026, 05:50 (UTC+9)Last seenJun 28, 2026Severity92ByCTX TeamIOC19MITRE25

At least seven command-and-control nodes spread across Indonesia, Brazil, Thailand, Mexico, and three additional unattributed locations are currently bound by a single hardcoded encoded URI path — /VJuPpCAAA/Vxi22CAAA/AHYe — embedded in a Cridex banking trojan payload that first surfaced in October 2012 and continues to generate active threat-feed hits.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence