
TA505 Rockloader C2 Hits SE Asia Finance With Zero Detections
A TA505-attributed rockloader campaign has built a three-domain command-and-control architecture targeting financial-services organisations in Cambodia and Singapore. All three domains, registered within five weeks, score zero detections across 91 antivirus engines, with WHOIS fields uniformly padded with a single 16-character hex token to defeat investigator pivoting.
A Single Hex Token, Two Registrars, and a C2 Architecture Built to Outlast Detection
Three command-and-control domains registered within five weeks of each other, scoring zero detections across 91 antivirus engines, with WHOIS identity fields uniformly padded with the same 16-character hex string — this is the operational signature CTX Team has mapped to a TA505-attributed rockloader campaign currently targeting financial-services organisations in Cambodia and Singapore. The infrastructure is live, unblocked, and generating no reputation signal on any major threat-intelligence platform at the time of collection.
The campaign's observable footprint is almost entirely confined to the network layer. Nine file SHA256s are cataloged, but none have been observed in VirusTotal, leaving the campaign's detection footprint confined almost entirely to the network layer. What remains is a three-domain C2 architecture whose construction reveals more about the operator's tradecraft discipline than any payload sample could: a Cloudflare-proxied primary zone registered in a single session with fabricated WHOIS identity, and a separately provisioned DGA-tagged beacon domain that resolves to the only concrete IP address in the entire catalog. The absence of file-level evidence means the infrastructure is the article, and the infrastructure is worth reading carefully.
The Gname.com Registration Session: One Operator, One Morning, One Hex Token
The timezoneapi.net zone was registered on 2026-05-18 at 09:51:24 UTC via Gname.com Pte. Ltd., a Singapore-incorporated domain registrar that has appeared in prior infrastructure clusters associated with threat actors operating out of East Asia. The apex domain and its subdomain sdyer.timezoneapi.net share an identical creation timestamp, an identical registrar, and — most distinctively — identical WHOIS registrant fields across every contact attribute the ICANN record requires.
Every field that would normally carry identifying information — registrant name, organisation, city, street address, postal code, state/province, phone, and fax — is set to the same hex string: ddb75a553547a419. The registrant country is listed as CN. The registrant email resolves to a malformed address. This is not sloppy form-filling; it is a deliberate identity-masking technique that satisfies ICANN's field-completion requirements while providing zero usable pivot data for investigators attempting to correlate registrant identity across domains. The hex token functions as a null value dressed as content.
The cohort significance here is straightforward: both domains were provisioned in a single operator session, under a single registrar account, with a single fabricated identity token. That same-day, same-registrar, same-registrant-token pattern is a strong single-operator fingerprint. An investigator who encounters either domain in isolation sees a newly registered .net domain with a Chinese-country registrant and Cloudflare nameservers. An investigator who sees both simultaneously sees the session boundary — the moment the operator stood up an entire C2 zone in one sitting.
The DNS delegation for the timezoneapi.net zone is handled by Cloudflare nameservers: morgan.ns.cloudflare.com and tina.ns.cloudflare.com. Forcepoint ThreatSeeker has categorised timezoneapi.net as "newly registered websites" — the only vendor categorisation present across any of the three domains — which reflects the domain's age rather than any behavioural detection. The Cloudflare proxy layer means that no A-record for the apex is exposed in passive DNS; the true hosting IP is concealed behind Cloudflare's anycast network, complicating both takedown requests directed at the hosting provider and any attempt to pivot from the domain to a hosting address.
The subdomain sdyer.timezoneapi.net inherits the same zone delegation and the same WHOIS obfuscation, since it is a record within the operator-controlled timezoneapi.net zone rather than a separately registered domain. Its naming — a five-character lowercase label that carries no obvious semantic meaning — is consistent with a dedicated beacon or tasking channel differentiated from the apex. The analyst's attack chain assessment treats this as a tiered C2 arrangement [T1090]: the apex domain serving as the primary C2 contact point, the named subdomain providing a separate path that could be used to differentiate victim beaconing, staging traffic, or operator tasking within the same registered zone. This structural reading is consistent with rockloader C2 architecture as CTX Team understands it from the campaign's technique attribution, though direct confirmation from sandbox output is not available.
At the time of collection, sdyer.timezoneapi.net scores 0/91 on VirusTotal with zero community votes. The apex timezoneapi.net scores identically. Neither domain carries any TLS certificate, which eliminates certificate serial number and Subject Alternative Name linkage as cross-domain correlation axes — a gap that materially constrains the pivot surface available to investigators.
babyyyi.com: The Throwaway Node That Breaks the Pattern
Eighteen days after the Gname.com registration session, on 2026-06-05 at 13:51:31 UTC, a third domain entered the campaign's infrastructure — and it was provisioned through an entirely different registrar, with different nameservers, and a concrete A-record that the timezoneapi.net cluster deliberately withholds.
babyyyi.com was registered via NameSilo, LLC — the only NameSilo registration in this catalog — and delegated to ns1.domainnamens.com and ns2.domainnamens.com rather than Cloudflare. It resolves to a single A-record: 137.220.156.123, with a TTL of 600 seconds. That short TTL is operationally significant. A 600-second record lifetime means that a defender who blocks the IP can expect the operator to rotate to a new address within ten minutes of the block taking effect, and that the DNS resolution chain will reflect the change almost immediately. It is a configuration choice that prioritises operational resilience over infrastructure stability.
The domain carries a dga tag in VirusTotal's metadata — the only DGA-tagged domain in this catalog. Its lifespan footprint at the time of collection was 18 days between creation and last observed activity. At 19 days old when CTX Team collected it, babyyyi.com is a throwaway beacon node: registered recently, pointed at a single unanchored IP, delegated through a nameserver pair (domainnamens.com) that provides no Cloudflare-style proxy anonymity but also carries no reputation signal, and already tagged with a classification that marks it as algorithmically generated or operationally disposable [T1568.002].
The registrar divergence from the Gname.com cluster is the analyst's primary outlier signal. The two infrastructure fingerprints — the "Gname.com-registered timezoneapi.net cluster" and the "Fresh NameSilo domain babyyyi.com" — share no registrar, no nameserver provider, no registration date, and no WHOIS token. What they share is the campaign: the same actor attribution, the same target profile, the same zero-detection status across 91 engines. The operational reading is that babyyyi.com was provisioned as a separately managed, short-rotation beacon domain designed to maintain C2 resilience if the primary timezoneapi.net zone is blocked or sinkholed. The two-registrar architecture means that a takedown or blocklist action against one registration account does not automatically surface the other domain.
The IP address 137.220.156.123 is the only concrete hosting address in the entire catalog. Current evidence is too thin to attribute an ASN, hosting provider, or certificate history to this IP — making it the highest-value enrichment target in the catalog. ASN lookup, hosting provider identification, passive DNS history, and historical certificate data for that IP could materially upgrade the current confidence assessment and potentially link this infrastructure to prior TA505 operational clusters. That enrichment work is outside the scope of this analysis.
babyyyi.com scores 0/91 on VirusTotal with zero community votes and zero reputation score. No TLS certificate is present. The WHOIS record, unlike the timezoneapi.net entries, does not use hex-token obfuscation — the NameSilo registration process redacts registrant data by default under privacy protection, so the absence of a fabricated identity token here reflects registrar policy rather than a different operational approach to identity concealment.
The Detection Gap: Why 0/91 Matters More Than It Usually Does
A 0/91 detection score is not, by itself, unusual for a newly registered domain with no observed malicious traffic in VirusTotal's telemetry. What makes the uniform zero-detection status across all three domains analytically significant in this case is the combination of factors that would normally generate at least partial detection signal — and don't.
The timezoneapi.net apex was registered 37 days before the CTX Team collection date. That is enough time for domain-reputation systems, newly-registered-domain feeds, and passive DNS enrichment pipelines to have processed it. Forcepoint ThreatSeeker did categorise it as "newly registered websites" — but that is an age-based category, not a threat verdict, and it generates no AV detection. No other vendor has moved it out of the clean bucket. The subdomain sdyer.timezoneapi.net, which inherits the zone's Cloudflare delegation and therefore generates no exposed A-record for reputation systems to evaluate against hosting-IP blocklists, has similarly accumulated zero detections in 28 days of observable activity.
babyyyi.com, at 19 days old, has had less time in the corpus — but its DGA tag, its short-TTL A-record, and its NameSilo registration pattern are exactly the profile that domain-generation-algorithm detection heuristics are designed to flag. None of the 91 engines have done so.
The complete absence of TLS certificates across all three domains removes one of the most reliable cross-domain linkage mechanisms available to threat intelligence analysts. Certificate serial numbers, Subject Alternative Name lists, and issuer chains are frequently the thread that connects infrastructure registered under different identities, different registrars, and different hosting providers. When an operator builds C2 infrastructure without deploying TLS certificates — or deploys certificates that have not yet been submitted to Certificate Transparency logs — they eliminate that entire pivot surface. Whether the absence of certificates reflects a deliberate operational choice, a collection timing gap, or the use of non-CT-logged certificates is not determinable from current evidence.
The nine cataloged file SHA256s compound the detection gap. None have been observed in VirusTotal, leaving the payload-level detection surface — which would normally provide the richest signal for AV-based blocking, EDR rule matching, and YARA hunting — entirely absent. The campaign is, from a detection-signal perspective, operating in a clean environment: no domain reputation hits, no file-hash detections, no certificate serial matches, no community votes flagging any of the infrastructure as malicious.
That is not a coincidence. It is the operational objective.
The Inferred Kill Chain: What the MITRE Attribution Suggests About the Payload
Because the nine cataloged file SHA256s carry no VirusTotal metadata, the payload-stage analysis in this section is explicitly inferred from the MITRE technique set attributed to the campaign. CTX Team treats these as technique-level indicators of the rockloader operational pattern rather than directly confirmed behaviours — readers should weight them accordingly.
The attributed technique set spans the full execution lifecycle. At the delivery stage, the pattern suggests user execution [T1204] of obfuscated files [T1027, T1027.013] — encrypted or encoded payloads that require a user action to trigger, consistent with phishing-delivered loaders targeting financial-sector employees. Before detonating the primary payload, the loader appears to perform time-based sandbox and virtualisation evasion checks [T1497.003], gating execution to environments that pass a live-host heuristic. This is a standard anti-analysis gate: if the execution environment looks like a sandbox — wrong timing, wrong process count, wrong hardware fingerprint — the loader either exits cleanly or delivers a benign decoy payload.
On a live host, the execution stage involves scripted components via PowerShell [T1059.001] and the Windows Command Shell [T1059.003], with process injection via extra window memory [T1055.011] used to mask the implant under a legitimate host process. Extra window memory injection is a relatively uncommon injection variant that exploits the per-window memory allocation in the Windows GUI subsystem — it is less frequently detected by EDR products that focus on the more common CreateRemoteThread and APC injection paths, which is likely why it appears in the rockloader technique set alongside the more standard process injection parent technique [T1055].
The post-exploitation collection profile is oriented toward reconnaissance and intelligence gathering rather than immediate financial fraud. Application window enumeration [T1010] profiles the victim's active applications — identifying open browser sessions, financial terminals, or security tools that might be visible in the window list. Registry querying [T1012] extracts system configuration, installed software inventory, and potentially stored credentials or application settings. Software discovery [T1518.001] complements the registry query with a broader installed-applications survey. Together, these techniques describe a victim-profiling phase consistent with an espionage-oriented collection objective: the operator wants to understand what the compromised host has access to before committing to deeper exfiltration.
Forensic suppression is also attributed to this campaign. File deletion [T1070.004] and timestomping [T1070.006] — the modification of file system timestamps to disguise when files were created, modified, or accessed — are both present in the technique set. Timestomping in particular is an artefact-suppression technique that directly targets forensic timeline reconstruction, making it harder for incident responders to establish when a loader was dropped or when a persistence mechanism was installed. Its presence alongside file deletion suggests the operator anticipates that the compromised host may eventually be subject to forensic examination and is taking steps to reduce the fidelity of that examination.
The C2 communication layer connects back to the infrastructure described above [T1090, T1568.002]. The tiered architecture — primary zone timezoneapi.net with subdomain sdyer.timezoneapi.net, backed by the rotating throwaway beacon babyyyi.com — provides the operator with redundancy: if the primary Cloudflare-proxied zone is blocked at the DNS level, the beacon domain provides an alternative contact path. The 600-second TTL on babyyyi.com's A-record means the operator can rotate the hosting IP faster than most blocklist update cycles.
One technique in the attributed set warrants specific note: T1559.002, which covers inter-process communication via Dynamic Data Exchange. DDE abuse has been documented in Office document delivery chains and is consistent with a phishing-delivered initial access vector, though current evidence does not include any URL or document-type file indicators that would confirm a document-based delivery mechanism. This is a gap in the observable chain rather than a confirmed absence.
TA505 and the Southeast Asian Financial-Sector Focus
TA505 — also tracked under the aliases Hive0065, SectorJ04, Graceful Spider, Chimborazo, Spandex Tempest, and Monty Spider — is the attributed actor for this campaign. CTX Team assesses the TA505 attribution at reasonably high confidence given the infrastructure and technique pattern, while acknowledging that the absence of file-level evidence prevents the kind of hash-level or signer-level confirmation that would push confidence to near-certainty.
The assessed motivation is espionage, and the targeted industries are financial services in Cambodia and Singapore. This combination — a financially sophisticated actor with an espionage motivation tag, operating against financial-sector targets in two Southeast Asian jurisdictions that host significant cross-border capital flows — is analytically interesting and currently unresolved.
The espionage motivation tag, combined with the collection-oriented MITRE technique set (window enumeration, registry querying, software discovery), is consistent with an intelligence-collection objective: credential harvesting, transactional data theft, or access-brokering into financial networks, rather than immediate wire-fraud or ransomware deployment. Whether this reflects a state-adjacent tasking — financial intelligence collection serving a government client — or a criminal actor conducting reconnaissance prior to a financial fraud operation is not determinable from current evidence. CTX Team rates the state-alignment inference as low-confidence; current evidence is too thin to conclude in either direction.
Cambodia and Singapore represent distinct financial-sector profiles. Singapore is a major regional financial hub with significant private banking, asset management, and fintech infrastructure. Cambodia hosts a growing cross-border payment ecosystem and has been the subject of financial-crime enforcement attention in recent years. The pairing of the two jurisdictions as targets suggests the operator is interested in the broader Southeast Asian financial corridor rather than a single national target.
What a Three-Domain, Zero-Detection Infrastructure Signals About Operational Maturity
The most analytically significant aspect of this campaign is not any individual technique or domain — it is the deliberate layering of operational-security measures across every observable dimension of the infrastructure, combined with a complete absence of detection signal that suggests the operator has calibrated the architecture specifically for the current detection landscape.
Consider what the operator chose to do at each decision point. At registration, they used a registrar — Gname.com Pte. Ltd. — that satisfies ICANN requirements while providing minimal friction for identity-obfuscated registrations, and they padded every WHOIS field with a hex token that is syntactically valid but informationally null. At DNS delegation, they chose Cloudflare nameservers for the primary zone, accepting the operational constraint of no direct A-record exposure in exchange for the proxy anonymity and DDoS resilience that Cloudflare provides. For the secondary beacon domain, they chose a different registrar entirely — NameSilo — with different nameservers, creating a two-registrar architecture that means a takedown action against one registration account does not automatically surface the other. They set the beacon domain's A-record TTL to 600 seconds, enabling rapid IP rotation. They deployed no TLS certificates that would appear in Certificate Transparency logs and create a cross-domain linkage axis. And they maintained nine file SHA256s in the threat catalog that carry no VirusTotal metadata — either because the payloads have not been submitted to VirusTotal, or because they were submitted under conditions that prevented metadata generation.
Each of these choices is individually unremarkable. Cloudflare proxying is common. NameSilo registrations are common. Short TTLs are common. DGA-tagged domains are common. What is notable is that every choice in this infrastructure points in the same direction: minimise the detection surface, maximise the pivot-resistance, and ensure that the infrastructure can continue operating even if individual components are identified and blocked.
The result is a campaign that is, at the time of collection, operationally live and generating no blocking signal from any of the 91 antivirus engines that evaluated the three domains. Financial-services organisations in Cambodia and Singapore that rely on domain-reputation feeds, AV-based web filtering, or certificate-serial blocklists have no current signal from this infrastructure. The detection gap is not a failure of any individual product — it is the intended outcome of the operator's infrastructure design.
The unanchored IP address 137.220.156.123 — the A-record for babyyyi.com, and the only concrete hosting address in the entire catalog — is the single highest-value enrichment target in this dataset. ASN identification, hosting provider attribution, passive DNS history, co-hosted domain enumeration, and historical TLS certificate data for that address could materially change the evidence picture. If the IP resolves to a hosting provider with a documented history of TA505 infrastructure, or if passive DNS reveals co-hosted domains that share registration patterns with the timezoneapi.net cluster, the current confidence assessment could be substantially upgraded. That enrichment work is the next analytical step.
The broader signal this campaign sends is about the direction of threat-actor infrastructure tradecraft. The combination of hex-token WHOIS obfuscation, multi-registrar architecture, Cloudflare proxy anonymity, DGA-tagged short-rotation beacon domains, and complete TLS certificate absence is not a novel technique set — each element has been documented in prior campaigns. What is notable is the systematic application of all of them simultaneously, in a campaign that targets a specific sector and region with an espionage motivation, and that has achieved complete evasion of automated detection at the time of collection. The operator is not experimenting with evasion techniques; they are executing a rehearsed operational-security protocol. That level of infrastructure discipline, applied to financial-sector targets in Southeast Asia with an espionage motivation tag, suggests an actor that has moved well past opportunistic tooling reuse and into deliberate, repeatable campaign architecture — and that is the most important thing this three-domain infrastructure communicates.