C&CMembers
C&C

Ludashi Campaign Staged Eight C2 Subdomains Four Months Before First Payload

A single-batch domain registration on 2025-03-10 provisioned the entire xhyktech.com subdomain estate months before any malicious binary appeared. Three subdomains now share an iTrust wildcard TLS certificate, with payload delivery routed through Alibaba Kunlun CDN chains that make campaign traffic indistinguishable from legitimate Alibaba infrastructure egress.

Jun 4, 2026, 23:40 (UTC+9)Last seenJun 4, 2026Severity100ByCTX TeamIOC33MITRE43

Since CTX Team's earlier coverage established the signed-binary tradecraft at the core of this operation, the picture of how those payloads reach victims has come into focus. The new signal is entirely network-side: eight xhyktech.com subdomains provisioned in a single registration batch on 2025-03-10, three of them now unified under a wildcard TLS certificate issued by the Chinese CA iTrust, Inc.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence