APTMembers
APT

Ludashi Campaign Adds 13 Payloads, Tencent CDN Relay to Evasion Stack

Thirteen new Windows binaries signed under a single persistent DigiCert certificate have expanded the Ludashi-ecosystem campaign, accompanied by a four-subdomain C2 cluster and a Tencent Cloud API Gateway domain-fronting relay that makes malicious traffic indistinguishable from legitimate cloud API calls. The operator is not merely scaling volume — it is adding qualitatively more capable network-concealment techniques with each production cycle.

May 28, 2026, 01:59 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorTA551ShathakIOC69MITRE12

Thirteen new Windows PE32 binaries signed under a single DigiCert code-signing certificate have entered the Ludashi-ecosystem campaign since CTX Team's prior coverage, while a freshly provisioned four-subdomain C2 cluster under tjbxldkj.cn and a Tencent Cloud API Gateway domain-fronting relay on ss.dllfix.cn represent infrastructure capabilities that were absent from the earlier operation.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence