C&CMembers
C&C

Phorpiex Swaps Three Payloads While C2 Infrastructure Holds Firm

Three new PE32 executables entered Phorpiex's active file set as three prior payloads were retired, leaving command-and-control infrastructure untouched for the eighth consecutive observation window. Two of the three new binaries carry zero VirusTotal metadata, arriving below the scanner threshold by design. The asymmetry — rotating the file layer while protecting the network layer — signals deliberate operational discipline rather than reactive evasion.

Jun 10, 2026, 13:03 (UTC+9)Last seenJun 18, 2026Severity100ByCTX TeamIOC9MITRE33RegionsPK

Three new PE32 executables have entered the Phorpiex botnet's active file set while three prior payloads were simultaneously retired — a clean swap that leaves the campaign's command-and-control backbone untouched for the eighth consecutive observation window. The rotation is surgical: the two C2 IP addresses, the wildcard certificate architecture anchored to *.certsdom.com, and the staging URL pattern under tsrv2.top all persist unchanged, while the operator pushes fresh binaries through the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence