
Ludashi Campaign Adds 13 Payloads, Tencent CDN Relay to Evasion Stack
Thirteen new Windows binaries signed under a single persistent DigiCert certificate have expanded the Ludashi-ecosystem campaign, accompanied by a four-subdomain C2 cluster and a Tencent Cloud API Gateway domain-fronting relay that makes malicious traffic indistinguishable from legitimate cloud API calls. The operator is not merely scaling volume — it is adding qualitatively more capable network-concealment techniques with each production cycle.
Thirteen new Windows PE32 binaries signed under a single DigiCert code-signing certificate have entered the Ludashi-ecosystem campaign since CTX Team's prior coverage, while a freshly provisioned four-subdomain C2 cluster under tjbxldkj.cn and a Tencent Cloud API Gateway domain-fronting relay on ss.dllfix.cn represent infrastructure capabilities that were absent from the earlier operation.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read