C&CMembers
C&C

Russian Hosting Tier Joins njRAT Campaign's Free-Cloud C2 Stack

Two Russian IPs on NUBES LLC infrastructure now serve the same malware payload directly, alongside the campaign's usual free PaaS fronting. One host wears a forged FortiGate certificate; its subnet twin still runs a decade-expired default cert.

Jul 4, 2026, 19:54 (UTC+9)Last seenJul 4, 2026Severity100ByCTX TeamIOC25MITRE45RegionsAE

Two IP addresses added to this record in the latest enrichment pass — 176.111.174.140 and 176.111.174.177 — sit inside the same /24 block, 176.111.174.0/24, registered to NUBES LLC under AS212136 in Russia. Both serve the identical delivery path, /bin/bot64.bin, directly by IP address rather than through a fronted domain. That is a meaningful departure from the campaign's earlier profile, which leaned almost entirely on free platform-as-a-service (PaaS) and CDN infrastructure — Render,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence