C&CMembers
C&C

One Plesk Cert Ties Four Lumma Stealer .su Domains Together

Four newly registered .su domains resolve to the same Proton66-hosted IP, share one reg.ru nameserver pair, and present an identical Let's Encrypt certificate hard-coded to the server's IP — exposing a single Plesk-based C2 pool behind what looked like separate infrastructure. The payload riding on it is Lumma Stealer, delivered via a near-invisible VBA macro lure and a Wextract-impersonating dropper.

Jun 28, 2026, 02:03 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC34RegionsCLRO

Four freshly minted .su domains — bendavo.su, conxmsw.su, narroxp.su and squeaue.su — all resolve to the same Russian-hosted IP address, share the same pair of nameservers, and present, byte for byte, an identical TLS certificate. That last detail is the tell: the certificate's subject alternative name literally hard-codes the hosting IP address into its hostname, a fingerprint that exposes what looks like four independent command-and-control domains as a single rotating front end sitting…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence