
Russian Hosting Tier Joins njRAT Campaign's Free-Cloud C2 Stack
Two Russian IPs on NUBES LLC infrastructure now serve the same malware payload directly, alongside the campaign's usual free PaaS fronting. One host wears a forged FortiGate certificate; its subnet twin still runs a decade-expired default cert.
Two IP addresses added to this record in the latest enrichment pass — 176.111.174.140 and 176.111.174.177 — sit inside the same /24 block, 176.111.174.0/24, registered to NUBES LLC under AS212136 in Russia. Both serve the identical delivery path, /bin/bot64.bin, directly by IP address rather than through a fronted domain. That is a meaningful departure from the campaign's earlier profile, which leaned almost entirely on free platform-as-a-service (PaaS) and CDN infrastructure — Render,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read