C&C
218 stories
C&CMembersJul 1, 2026, 06:15 (UTC+9)A Miner Wearing the Face of a Visual C++ Runtime
##A Miner Wearing the Face of a Visual C++ Runtime A packed .NET coinminer masquerading as the Microsoft Visual C++ runtime file msvcp110.exe has replaced the dropper payloads in a campaign CTX Team has been tracking since April, marking a clear pivot from delivery-stage malware to direct resource hijacking. The new primary binary — a 774 KB PE32+ assembly first submitted on 2026-04-17 — deploys into C:\Users\[user]\AppData\Roaming\msvcp110_win\msvcp110.exe, a user-writable path whose filename…
#coinminer#XMRig#msvcp110.exe#.NETpackedbinary#MSIL/Bobik#PureLogStealer#ContaboC2#IraqSouthKoreaTurkeyIOCf2 · i1 · d0 · u3MITRE36RegionsIQ · KR · TR
C&CMembersJun 29, 2026, 09:09 (UTC+9)KMSAuto Crack Lure Delivers Five-Stage Crimeware Chain From One Workbench
A trojanized KMSAuto Lite v1.6.5 Windows activation crack is circulating as the delivery vehicle for a tightly assembled five-component crimeware toolkit — one whose most distinctive feature is not the individual payloads it carries, but the build discipline that holds them together. Three of the five payload components share an identical expired Microsoft Windows Publisher leaf certificate, two others share a self-signed WZTeam certificate applied on the same day, and the PS2EXE toolchain used…
#Amadey#ClipBanker#AZORult#KMSAutolure#PS2EXE#certificatespoofing#cryptocurrencytheft#RussiaIOCf7 · i1 · d0 · u3MITRE43RegionsUG
C&CMembersJun 29, 2026, 05:23 (UTC+9)Lumma Stealer Hides Behind Iranian ISP and Seychelles Shell in Domainless C2
Four raw IP addresses. No domains. One hardcoded path. That is the entirety of the network-layer architecture behind a Lumma Stealer campaign that has been circulating since October 2025 under the filename "BTC CRACKER.exe" — a lure aimed squarely at cryptocurrency users who believe they are downloading a wallet-cracking utility.
#LummaStealer#Diamotrix#bulletproofhosting#cryptocurrencytheft#domainlessC2#FarahooshDenaPLC#OmegatechLTD#credentialharvestingIOCf1 · i4 · d0 · u8MITRE33RegionsUS
C&CMembersJun 29, 2026, 01:09 (UTC+9)Layered Windows Trojan Campaign Hits India With Zero-Detection Loader
Six unsigned Windows executables and DLLs, all carrying copyright strings dated decades into the future, have surfaced across a three-week window targeting India — the product of a disciplined build operation that deploys three structurally distinct payload layers, beacons to a Dynu dynamic-DNS node over deliberately malformed HTTP requests, and has achieved complete evasion of all 76 antivirus engines for its most recently submitted loader stage.
#ABMRisk#Kepavll#UPX-packedDLL#PEiDloader#dynamicDNSC2#sandboxevasion#India#WindowstrojanIOCf6 · i2 · d14 · u0MITRE22RegionsIN
C&CMembersJun 28, 2026, 10:02 (UTC+9)2345Pinyin Pipeline Grows Fallback Channel as Fuzhou IP Breaks Brand Pattern
Two newly observed IP addresses have extended the confirmed update-and-configuration infrastructure behind the 2345Pinyin input-method editor to five distinct Chinese carrier networks — and one of those IPs presents a TLS certificate that sits entirely outside the established brand ecosystem the pipeline has relied on for years.
#2345Pinyin#IMEadware#C2infrastructure#TLScertificateabuse#Chinacarriernetworks#ad-injection#supplychaindelivery#certfallback.comIOCf44 · i5 · d0 · u0MITRE24RegionsCN
C&CMembersJun 28, 2026, 06:04 (UTC+9)Aged Vietnamese Domain Reissued as C2 Behind Evasive .NET Loader
A three-year-old Vietnamese domain, canhtrang.com, has resurfaced with a freshly issued 89-day TLS certificate and a self-signed administrative host that binds directly to a single evasive Windows loader — a pattern that looks less like a new campaign standing up infrastructure from scratch than an old, ordinary-looking licensing backend being quietly repurposed for command-and-control. The domain's free., lic., and ping.
#commandandcontrol#Vietnamhostinginfrastructure#TLScertificateabuse#loadermalware#.NETpacker#softwarelicensingabuse#sandboxevasion#domainrepurposingIOCf3 · i2 · d1 · u9MITRE23
C&CMembersJun 28, 2026, 05:50 (UTC+9)Cridex C2 Pool Spans Seven Nodes Across Four Continents on One Encoded Path
At least seven command-and-control nodes spread across Indonesia, Brazil, Thailand, Mexico, and three additional unattributed locations are currently bound by a single hardcoded encoded URI path — /VJuPpCAAA/Vxi22CAAA/AHYe — embedded in a Cridex banking trojan payload that first surfaced in October 2012 and continues to generate active threat-feed hits.
#Cridex#Zbot#bankingtrojan#C2infrastructure#invoicelure#multi-noderesilience#Indonesia#MexicoIOCf3 · i4 · d0 · u12MITRE25
C&CMembersJun 28, 2026, 02:03 (UTC+9)One Plesk Cert Ties Four Lumma Stealer .su Domains Together
Four freshly minted .su domains — bendavo.su, conxmsw.su, narroxp.su and squeaue.su — all resolve to the same Russian-hosted IP address, share the same pair of nameservers, and present, byte for byte, an identical TLS certificate. That last detail is the tell: the certificate's subject alternative name literally hard-codes the hosting IP address into its hostname, a fingerprint that exposes what looks like four independent command-and-control domains as a single rotating front end sitting…
#LummaStealer#commandandcontrolinfrastructure#Pleskpanel#Proton66#domainrotation#VBAmacromalware#Wextractmasquerading#commodityinfostealerIOCf18 · i2 · d5 · u9RegionsCL · RO
C&CMembersJun 27, 2026, 09:20 (UTC+9)36 'sslsecure' Domains Mask a Templated Adware Pipeline
Thirty-six hostnames sit behind an indicator set that VirusTotal enrichment and registrar records tie to a single naming convention: sslsecure<N>.com, reproduced apex-for-apex with an identical api.v2., track.v2., and staticrr. subdomain triplet bolted onto each one. The pattern runs from sslsecure2.com through sslsecure10.com, and it isn't cosmetic — it's a templated hosting fabric built to look, at a glance, like generic SSL or security infrastructure rather than adware plumbing.
#domaiq#PUP/adware#domaininfrastructure#registrarabuse#codesigningabuse#USretailsector#ztomy.comnameservers#masqueradingIOCf2 · i1 · d36 · u0MITRE29RegionsUSIndustriesRetail
C&CPublicJun 27, 2026, 05:28 (UTC+9)Amadey Credential Stealer Slips Past Sandbox Despite 60/79 AV Flags
Sixty of seventy-nine antivirus engines call it outright malicious. Feed the same file to a sandbox, and it comes back clean — "undetected," classified only as UNKNOWN_VERDICT, zero out of one dynamic runs flagging anything at all. That is the story sitting inside a single Amadey-linked credential-stealer DLL, tracked internally as cred.dll, and it is a more useful data point than most of the noisier campaign narratives this desk sees in a given week: a textbook illustration of how a passive…
#Amadey#credentialstealer#DLLmalware#sandboxevasion#C2infrastructure#Russia#YARAdetection#PleskhostingIOCf2 · i1 · d0 · u1MITRE10RegionsBG
C&CMembersJun 27, 2026, 05:07 (UTC+9)A 2012 Domain Registration Still Feeds a Fake Firefox Installer Today
Three domains bulk-registered on a single day in October 2012 are still actively serving software downloads today, and CTX Team's infrastructure mapping ties the pair of IP addresses behind their apparent callback layer to a shared TLS certificate spanning two European countries under one Brazilian CDN provider's autonomous system.
#DealPly#PUPdistribution#Baixaki#AzionTechnologies#code-signingbypass#Firefoximpersonation#CDNinfrastructure#BrazilIOCf7 · i2 · d3 · u1MITRE34RegionsBRIndustriesTechnology
C&CPublicJun 26, 2026, 17:36 (UTC+9)Upatre C2 Network Hides in Hungarian and Rural US ISP Space
A 74-kilobyte Windows executable disguised as a scanned business document sits at the centre of a command-and-control network that deliberately avoids the commercial hosting fabric most threat-intelligence feeds are tuned to watch. Both enriched relay nodes in this campaign occupy address space belonging to small, non-commercial internet service providers — one a Hungarian broadband operator in Budapest, the other a rural telephone cooperative in the American Midwest — while three additional C2…
#Upatre#C2infrastructure#spearphishingattachment#foodandbeverages#Italy#regionalISPabuse#downloadermalware#PE32stubIOCf3 · i2 · d0 · u5RegionsITIndustriesFood & Beverages
C&CMembersJun 26, 2026, 17:23 (UTC+9)1997-Timestamped Malware Resurfaces With 2025 C2 Infrastructure
A single unsigned Win32 executable, first submitted to VirusTotal in June 2015 and carrying a PE timestamp deliberately set to October 1997, is appearing alongside command-and-control infrastructure provisioned as recently as December 2025 — a temporal gap of more than a decade that sits at the heart of one of the more analytically interesting evasion puzzles CTX Team has examined this cycle. The payload targets consulting-sector organisations in the United States.
#consultingsector#PEtimestampmanipulation#sandboxevasion#C2infrastructure#indicatorremoval#packedmalware#UnitedStates#debuggerevasionIOCf3 · i2 · d0 · u5MITRE16RegionsUSIndustriesConsulting
C&CPublicJun 26, 2026, 09:35 (UTC+9)Cracked-Software Lure Bundles Three RAT Families From One Build Pipeline
A trojanised archive circulating under the name "Onimai 1.7.1" — presented to prospective victims as a cracked copy of a software application — packages three distinct remote-access trojan families into a single deployment bundle, all compiled from what the evidence indicates is a unified .NET build pipeline and routed through the playit.gg public tunnelling service to a self-signed command-and-control node registered in the Seychelles but geolocated in Germany.
#MrThunker#QuasarRAT#XWorm#VenomRAT#cracked-softwarelure#playit.ggtunnelling#FodyCosturapacking#commodityRATIOCf9 · i1 · d0 · u1
C&CPublicJun 25, 2026, 17:58 (UTC+9)Finance-Lure VBScript Spoofs CSV Type to Evade Static Scanners
Three new file variants have surfaced in an ongoing Formbook delivery campaign that CTX Team has been tracking since its prior coverage (earlier coverage), and the most significant change is not a new payload family or a fresh infrastructure node — it is a quiet manipulation of file-type metadata. The outer ZIP container drops a VBScript downloader whose file magic is reported as "CSV text" despite carrying a .vbs extension and an uncompressed size of nearly two megabytes, a type-confusion…
#Formbook#VBScript#file-typespoofing#financelure#commodityinfostealer#phishingattachment#C2infrastructure#accounts-payabletargetingIOCf3 · i0 · d1 · u2RegionsBD · BE · CA · CHIndustriesAerospace · Construction · Consulting
C&CMembersJun 25, 2026, 17:35 (UTC+9)One Ukrainian IP, Four One-Letter Payloads, Zero Sandbox Alarms
A 182-kilobyte Windows executable that 63 of 75 static antivirus engines flag as malicious walks through dynamic analysis without triggering a single sandbox alarm. That contradiction — near-universal static detection paired with a 99-confidence CLEAN verdict from Zenbox — sits at the centre of an active Phorpiex-and-GandCrab distribution operation whose entire observable infrastructure collapses to a single Ukrainian IP address, 92.63.197.106, operating under ASN 211736 (FOP Dmytro Nedilskyi).
#Phorpiex#GandCrab#sandboxevasion#single-IPinfrastructure#ransomwaredistribution#Ukraine#wormpropagation#dropperIOCf4 · i1 · d0 · u6MITRE38RegionsCN
C&CPublicJun 25, 2026, 05:44 (UTC+9)Purchase-Order VBS Downloader Now Delivers XWorm, Not Formbook
A VBS script disguised with a CSV file signature — the same purchase-order-themed downloader CTX Team tracked in earlier coverage of this delivery chain — now sandboxes to a different terminal payload entirely. Where the prior reporting on this lineage centered on a Formbook loader, the newly submitted sample returns a 3/3 malicious consensus across CAPE Sandbox, Zenbox, and Yomi Hunter, with the sandbox layer explicitly naming the deployed family as XWorm, a commodity remote-access trojan.
#XWorm#Formbook#VBScriptdownloader#purchaseorderlure#basefile.click#KeyAuth#remoteaccesstrojan#phishingIOCf3 · i0 · d1 · u2RegionsAT · AU · BD · CAIndustriesCommercial Services · Education & Research · Government
C&CPublicJun 25, 2026, 01:55 (UTC+9)DCRat Campaign Hides C2 Traffic Behind Fake Google Analytics TLS Cert
A single attacker-controlled domain is currently staging a DCRat remote-access trojan behind a TLS certificate whose subject common name reads *.google-analytics.com — a deliberate impersonation of Google's telemetry infrastructure designed to make outbound C2 traffic appear, to any network sensor performing only certificate-level inspection, as routine analytics beaconing.
#ManicMenagerie#DCRat#TLScertificateimpersonation#Germany#bulletproofhosting#authenticodeevasion#C2infrastructure#packedmalwareActorsManic MenagerieIOCf1 · i1 · d1 · u2RegionsDE
C&CMembersJun 24, 2026, 13:54 (UTC+9)Upatre Downloader Returns With Anti-Analysis Stack Shielding FTP C2
Three Windows PE droppers surfaced in CTX Team's feed on June 24, 2026, carrying a threat label that many defenders might dismiss on sight: Upatre, a downloader family old enough to have been circulating when the Czech ISP subnet it now phones home to was first registered. That familiarity is precisely the risk. The current cluster — tracked as CTX4uky7ju34a — pairs the family's well-worn FTP-based payload retrieval with a layered anti-analysis stack that sequences time-based sandbox checks…
#Upatre#FTPC2#anti-analysisevasion#CzechRepublicinfrastructure#downloader#sandboxevasion#securitytooldisablement#post-executioncleanupIOCf3 · i1 · d0 · u4MITRE13
C&CMembersJun 24, 2026, 10:03 (UTC+9)One PHP Path, Four Servers, Ten Years: Inside an APT's C2 Framework
Four IP addresses. One identical endpoint. The string /upload/_dispatch.php — replicated without variation across a quartet of Russian-hosted servers — is the clearest fingerprint CTX Team has extracted from a campaign carrying espionage motivation and APT classification in the threat record. The infrastructure has been operationally maintained from at least mid-2016 through confirmed certificate activity in June 2026, a decade-long window that makes the uniformity of that PHP path all the more…
#APT#C2infrastructure#PHPframework#Turkeyespionage#masquerading#dynamicimportresolution#self-signedcertificate#OPSECfailureIOCf14 · i2 · d11 · u7RegionsTR
C&CPublicJun 23, 2026, 17:22 (UTC+9)SWIFT-Lure ZIP Drops Formbook via 2 MB Sleep-Padded VBScript
A thirteen-kilobyte ZIP file named "Swift-015062026.zip" is circulating across at least 35 countries, carrying a single child file that expands to nearly two megabytes of VBScript — a deliberate size anomaly engineered to exhaust static scanners and outlast the time-boxed execution windows that automated sandboxes rely on. When a recipient opens the archive and runs the enclosed script, they are handing a Formbook infostealer a foothold on their machine, with credentials, keystrokes,…
#Formbook#VBScriptdropper#SWIFT-themedphishing#sandboxevasion#basefile.click#financialservices#infostealer#spear-phishingattachmentIOCf3 · i0 · d1 · u2RegionsAT · BA · BD · BEIndustriesAerospace · Construction · Consulting
C&CMembersJun 23, 2026, 09:22 (UTC+9)WoodyRAT C2 Expands With Ukrainian Node, Traefik Relay, and .biz Domain Pair
Since CTX Team's earlier coverage of this WoodyRAT-attributed infostealer campaign, the operator has not stood still. Fifteen new file indicators and five new domains have entered the observable set, but the most analytically significant additions are structural rather than volumetric: a Ukrainian-hosted C2 node (195.211.191.95, AS208949, Hbing Limited) that bridges into the existing German hosting cluster via a shared operator-generated wildcard certificate, two freshly registered .biz domains…
#WoodyRAT#infostealer#C2infrastructure#cryptocurrencywallettheft#Traefikreverseproxy#bulletproofhosting#Ukraine#TelegramexfiltrationIOCf42 · i4 · d5 · u7MITRE62
C&CMembersJun 22, 2026, 17:26 (UTC+9)Nine-File Toolchain With Zero PE Imports Targets Six Countries via Dedicated AS
Nine Windows executables, zero PE imports between them, and a dedicated binary whose sole purpose is to kill endpoint defenses before the rest of the payload stack arrives — this is the operational profile of a campaign CTX Team has been tracking since late May 2026, one that pairs an unusually complete evasion architecture with a purpose-built autonomous system that its operator has been quietly expanding for the better part of a year.
#WoodyRAT#BazarLoader#Amadey#ClipBanker#EDRbypass#AS214351#credentialharvesting#reflectiveDLLinjectionIOCf26 · i3 · d5 · u6MITRE66RegionsDZ · ES · ID · IT
C&CMembersJun 21, 2026, 16:41 (UTC+9)Phorpiex Botnet Adds Kernel Driver and Go Wallet Stealer in 2026 Upgrade
A Phorpiex botnet campaign active since early June 2026 has added two capabilities that sit well outside the family's historical playbook: a Bring-Your-Own-Vulnerable-Driver kernel component and a Go-runtime infostealer purpose-built to drain cryptocurrency wallet browser extensions. The combination — mass SMTP propagation, XOR-obfuscated PE droppers, XMRig cryptomining, kernel-driver abuse, and browser-extension credential harvesting, all consolidated on four command-and-control IPs inside a…
#Phorpiex#XMRig#BYOVD#WinRing0#Goinfostealer#cryptocurrencywalletharvesting#AS202412#SpainIOCf15 · i6 · d9 · u5MITRE36RegionsES · UZ
C&CMembersJun 21, 2026, 08:25 (UTC+9)37-Node Tox C2 Network Powers Resilient Browser Credential Stealer
A packed Windows credential stealer is communicating with its operators through five numbered Tox-protocol subdomains distributed across two operator-controlled domains — tox1.mf-net.eu through tox4.mf-net.eu and tox.libre.tw — backed by a relay network of 37 IP addresses spanning four distinct ASN cohorts that include FranTech Solutions (AS53667), iFog GmbH (AS34927), Hetzner Online GmbH (AS24940), and M247 Europe SRL (AS9009).
#BrowserStealerGeneric#Toxprotocol#credentialtheft#bulletproofhosting#DNS-over-HTTPSevasion#Let'sEncryptcertificateabuse#FranTechSolutions#WindowsmalwareIOCf1 · i37 · d3 · u5MITRE10
C&CMembersJun 21, 2026, 04:14 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Monero Mining Campaign
A financially motivated campaign active during the week of June 19–20, 2026 is deploying XMRig 6.26.0 Monero miners behind a three-layer evasion stack that most commodity cryptomining operations never bother to assemble: a LOLDrivers-listed vulnerable kernel driver to undermine endpoint defences, a self-signed loader dressed up with a same-day certificate to slip past casual signature checks, and a game-themed NSIS dropper to carry the whole package past users who think they are installing a…
#XMRig#WinRing0x64.sys#BYOVD#Monerocryptomining#LOLDrivers#NSISdropper#maliciouskerneldriver#game-themedlureIOCf53 · i1 · d3 · u0MITRE36
C&CMembersJun 20, 2026, 08:28 (UTC+9)Nine No-IP Subdomains, One Account: A .NET Trojan C2 Still Active in 2026
A single No-IP dynamic DNS account holds nine sequentially enumerated subdomains — incorrect.no-ip.biz through 8incorrect.no-ip.biz — each configured with 60-second TTL A records pointing to European residential IP addresses, each sharing the same nameserver cluster (NF1 through NF5.NO-IP.COM), and each ready to absorb C2 traffic the moment any sibling is blocked or sinkholed.
#trojan.barys#MSILtrojan#No-IPDDNS#C2infrastructure#dynamicDNSabuse#imphashclustering#EuropeanresidentialIPs#defenseevasionIOCf3 · i2 · d9 · u0MITRE37RegionsFR
C&CMembersJun 20, 2026, 04:26 (UTC+9)Cridex C2 Roster Ties Eight IPs to One Hardcoded URI Path
Eight IP addresses. Five autonomous systems. Four countries. One identical URI path burned into every beacon call. That is the architecture CTX Team documented when it mapped the command-and-control roster attached to a Cridex/Dreidel trojan sample that first appeared on VirusTotal in January 2013 but was re-observed as recently as June 2026.
#Cridex#Dreidel#C2infrastructure#hardcodedURI#compromisedserver#TLScertificateabuse#Canadahosting#PortugalIOCf2 · i4 · d0 · u16MITRE20
C&CPublicJun 19, 2026, 04:26 (UTC+9)XWorm RAT Hides Behind Purchase-Order ZIP and Pre-Armed Wildcard Infrastructure
##Purchase-Order ZIP Conceals a Three-Stage XWorm Delivery Chain Built on Pre-Armed Wildcard Infrastructure A compact, eleven-kilobyte ZIP archive named PO-000172483.zip is the opening move in a campaign that unfolds across five deliberate stages — evasion-hardened VBS execution, a stealthy compile-after-delivery intermediate, and XWorm RAT C2 over a Turkish-geolocated IP whose hosting fabric was provisioned weeks before the first malicious file appeared on the internet.
#XWorm#VBSdownloader#compile-after-delivery#purchase-orderlure#wildcardTLSinfrastructure#manufacturing#WhiteLabelServices#multi-stagedeliverychainIOCf9 · i1 · d2 · u3RegionsAT · BD · BR · CHIndustriesAerospace · Agriculture · Automotive
C&CMembersJun 18, 2026, 20:06 (UTC+9)Phorpiex Clipbanker Uses Six Greek-Letter C2 Endpoints to Steal Crypto
A 103-kilobyte Windows executable named wescgsvcs.exe — crafted to blend visually with legitimate Windows service binaries — has been quietly draining cryptocurrency wallets through one of the more methodical evasion stacks CTX Team has documented in this family class. The binary, confirmed as a Phorpiex/Fragtor trojan with a clipbanker payload, beacons to a single command-and-control server at 185.215.113.84 that exposes exactly six HTTP endpoints named in Greek alphabetical order: alpha,…
#Phorpiex#Fragtor#clipbanker#cryptocurrencytheft#command-and-controlinfrastructure#sandboxevasion#timestomping#clipboardhijackingIOCf4 · i1 · d0 · u7MITRE31
C&CMembersJun 17, 2026, 20:27 (UTC+9)Phorpiex Rotates All Payloads Again as C2 Holds Firm for Ninth Wave
##Phorpiex Swaps Its Entire Payload Stack — Again — While C2 Holds Firm for a Ninth Consecutive Wave Since earlier coverage documented the Phorpiex/Trik operator's discipline of rotating binaries while leaving command-and-control infrastructure untouched, that pattern has completed another full cycle. All three payload files present in this snapshot are new arrivals; all three files from the prior snapshot have been retired.
#Phorpiex#Trik#payloadrotation#sandboxevasion#C2infrastructure#telecommunications#Kazakhstan#PakistanIOCf3 · i2 · d0 · u4MITRE35RegionsKZ · PKIndustriesTelecommunications
C&CMembersJun 17, 2026, 08:34 (UTC+9)Stealc v2 Bypasses Chrome 127 Encryption in Crypto-Theft Campaign
A financially motivated operator has deployed a multi-stage credential-theft campaign built around two Stealc v2 payloads that implement a post-Chrome-127 app-bound encryption key decryptor — a deliberate capability upgrade that allows the malware to extract browser-stored credentials from modern Chrome profiles that earlier Stealc variants and most competing infostealers cannot reach.
#Stealcv2#DiamotrixClipper#Chromiumapp-boundencryptionbypass#reflectiveDLLinjection#clipbanker#bulletproofhosting#cryptocurrencytheft#infostealerIOCf11 · i5 · d0 · u10MITRE51RegionsCA
C&CMembersJun 17, 2026, 08:03 (UTC+9)Sality Botnet Hides C2 Traffic in GIF Requests Across Italian and Polish Hosts
Twenty-four HTTP GET requests. Two geographically disparate web servers. One 5-kilobyte image file. On the surface, a routine web browser fetching a logo. Underneath, an active Sality botnet cluster routing encrypted bot check-ins through parameterised image requests to compromised shared-hosting accounts in Italy and Poland — a beaconing architecture that has been generating fresh C2 traffic into mid-2026 from a core payload first submitted to VirusTotal in July 2010.
#Sality#SaltySpider#C2infrastructure#sharedhostingabuse#GIFsteganography#USBpropagation#Bangladesh#TofseeActorsSalty Spider · KuKuIOCf24 · i2 · d2 · u24RegionsBD
C&CMembersJun 14, 2026, 22:59 (UTC+9)Emotet C2 Hides Behind WordPress Paths on Aged Compromised Domains
Two compromised websites — one a Turkish-language platform, the other a social media aggregator — are currently serving as active command-and-control relay nodes for an Emotet campaign cluster, with their WordPress administrative and content directories repurposed as beaconing endpoints. The infrastructure fingerprint CTX Team has documented is precise: dotasarim.com/wp-admin/Dyz and socialplaymedia.com/wp-content/Czj function as the actual C2 URLs, their paths indistinguishable at a glance…
#Emotet#Emotetepoch2#TA542#WordPressC2#command-and-controlinfrastructure#macro-enabledlure#TimewebASN9123#compromisedwebsitesActorsEmotet Group · TA542IOCf3 · i1 · d2 · u4
C&CPublicJun 14, 2026, 14:39 (UTC+9)Phorpiex Worm's Three-Layer Evasion Stack Keeps 20 AV Engines Blind
A 77-kilobyte Windows executable — small enough to be dismissed as a stub, old enough to have first appeared on VirusTotal in October 2020 — is still generating active C2-server feed hits as of mid-2026. The sample, carrying the threat label trojan.phorpiex/zard and the deceptively mundane meaningful name DriveMgr.exe, is not remarkable for its size or age alone.
#Phorpiex#Zard#worm#packedPE#C2infrastructure#TLSevasion#MEVSPACE#GuatemalaIOCf3 · i2 · d0 · u3MITRE34RegionsGT
C&CMembersJun 14, 2026, 02:57 (UTC+9)Two Ghost Payloads Blind Analysts as Emotet Relay Cluster Holds Steady
Since CTX Team's earlier coverage of this Emotet C2 cluster — documented in the prior article tracking the campaign's 89-day Let's Encrypt rotation pattern — two new file samples have entered the payload layer with zero VirusTotal enrichment: no file type, no detection ratio, no behavioural tags, no signer data. The infrastructure they connect to is unchanged and already fingerprinted. The payloads themselves are, at this moment, analytically invisible.
#Emotet#TA542#MummySpider#C2infrastructure#Let'sEncryptcertificaterotation#WordPressrelay#payloadcycling#RomaniaActorsEmotet Group · TA542IOCf3 · i1 · d3 · u4RegionsRO
C&CMembersJun 14, 2026, 02:41 (UTC+9)Emotet-Labeled Loader's TLS Handshake Trips Dridex IDS Rules
A Win32 loader DLL tracked in this cluster — 65 of 77 engines flag it, and Zenbox, VMRay, and C2AE all name it Emotet in a unanimous 3/3 sandbox verdict — trips two independent intrusion-detection rules built for an entirely different crimeware family. The DLL's outbound TLS handshake fires "ET JA3 Hash - [Abuse.ch] Possible Dridex" from Proofpoint's Emerging Threats Open ruleset and a second hit from Abuse.ch's SSLBL malicious JA3 fingerprint list, also tagged Dridex.
#Emotet#Dridex#JA3fingerprint#Excel4macromaldoc#loaderDLL#TA542#commodityhostinginfrastructure#sandbox-evasionActorsEmotet Group · TA542IOCf4 · i3 · d2 · u7RegionsRO
C&CMembersJun 13, 2026, 14:47 (UTC+9)BazLoader, Amadey, and StealC V2 Chain Targets Algeria and Italy via Single German /24
A 170-kilobyte PE32 dropper first submitted to public scanning infrastructure on 12 June 2026 is the entry point for one of the more operationally compact espionage-oriented loader chains CTX Team has tracked this quarter. The binary — identified as BazLoader/egairtigado and observed in the wild as sprd2.exe — touches down in the user Temp directory, copies itself to C:\Windows\8amu8dw.exe, and immediately begins beaconing over raw IPv4 HTTP to a pair of hosts consolidated within the…
#BazLoader#Amadey#StealCV2#WoodyRAT#AS214351#credentialharvesting#Algeria#ItalyIOCf30 · i2 · d0 · u5MITRE62RegionsDZ · IT
C&CMembersJun 13, 2026, 14:32 (UTC+9)woody_rat Stealer Drains Exodus and ElectronCash Wallets via Telegram Log Market
##Wallet Vaults Cracked Open: How a woody_rat Infostealer Pipeline Drains Exodus and ElectronCash in a Single Pass A woody_rat operation tracked by CTX Team has been systematically dismantling the cryptocurrency holdings of technology-sector victims in Egypt and Hungary, harvesting the full wallet store of both Exodus and ElectronCash installations in a single automated sweep — then packaging the stolen files into dated log archives and routing them through a Telegram bot channel for downstream…
#woody_rat#infostealer#Exoduswallet#ElectronCash#Telegramlogmarket#cryptocurrencytheft#Egypt#HungaryIOCf68 · i2 · d0 · u3MITRE62RegionsEG · HUIndustriesTechnology
C&CPublicJun 13, 2026, 10:39 (UTC+9)Fake Android Toolkit Delivers Sandbox-Proof Python Spyware
A self-extracting RAR archive named "Android Win Tool v1.9.6" is circulating as a trojanized utility lure, staging a PyInstaller-packed Python trojan and a secondary unsigned PE payload that beacon to parameterized HTTPS endpoints across a purpose-built two-tier command-and-control infrastructure. The campaign — tracked by CTX Team under threat record CTXkz7eez4uc5 with severity 100 and confidence 85 — is distinguished not by any single technique but by the deliberate layering of evasion…
#PyInstallertrojan#sandboxevasion#espionage#C2infrastructure#SFXarchivelure#Androidtoolkitlure#Let'sEncryptautomation#spywareIOCf26 · i2 · d3 · u3
C&CPublicJun 13, 2026, 10:27 (UTC+9)Phorpiex Relay Cluster Exposed by Misplaced TLS Certificate on Spam Domain
Five mail-themed domains provisioned across two registrar accounts, a freshly compiled 18 KB loader carrying an XOR-obfuscated C2 address, and a TLS certificate whose subject field names a spam-trap tracking domain — together these artefacts paint a Phorpiex spam botnet operation whose infrastructure cohesion is unusually legible.
#Phorpiex#spambotnet#mailrelayinfrastructure#TLScertificateanomaly#XORobfuscation#domainregistration#C2servers#HondurasKyrgyzstanUnitedStatesIOCf4 · i4 · d54 · u1RegionsHN · KG · US
C&CMembersJun 11, 2026, 19:10 (UTC+9)Twenty IPs, One Certificate: How a Phorpiex C2 Pool Mimics 2345.com
Eight of the twenty IP addresses flagged as command-and-control infrastructure for a financially motivated operation tracked under the phorpiex family sit inside a single China Telecom autonomous system, AS4811 — and five of those nodes present an identical TLS certificate, serial d3d9e9261c1c88d957e704d69617a469, whose subject reads *.2345.com.
#Phorpiex#C2infrastructure#TLScertificatereuse#ChinaTelecomAS4811#2345.comspoofing#adware/PUAinstaller#sslTrusCA#financiallymotivatedthreatactorIOCf3 · i27 · d0 · u0MITRE20RegionsCN
C&CMembersJun 11, 2026, 15:27 (UTC+9)Amadey Stealer Runs 67-IP C2 Pool Engineered to Outlast Blocklists
Sixty-seven IP addresses. One stealer binary. And an infrastructure architecture so deliberately fragmented that no single takedown pathway touches more than a fraction of it. That is the operational picture CTX Team has assembled around a currently active Amadey stealer deployment — a campaign whose most distinctive feature is not the malware itself but the tiered, multi-continent command-and-control fabric the operators have constructed around it.
#Amadey#stealer-as-a-service#C2infrastructure#KoreaTelecomAS4766#Let'sEncryptcertificaterotation#Brazilacademicnetwork#credentialharvesting#processinjectionIOCf1 · i67 · d0 · u2MITRE30
C&CMembersJun 11, 2026, 14:58 (UTC+9)MSIL/Bobik Dropper Stays Live as Mystery Second File Hints at New Payload
A 982-kilobyte unsigned .NET assembly — its PE timestamp deliberately forged to the year 2085 to confound timeline-based triage, its primary code section packed to an entropy of 7.64 — has been confirmed active as recently as 23 June 2026, deploying an XMRig-compatible cryptocurrency miner and PureLog credential stealer simultaneously to compromised endpoints across six industry verticals and 42 countries.
#MSIL/Bobik#PureLogStealer#XMRig#Contaboinfrastructure#credentialtheft#cryptocurrencymining#packed.NETdropper#multi-countrytargetingIOCf2 · i1 · d0 · u3MITRE37RegionsAR · AT · AU · BEIndustriesCommercial Services · Education & Research · Government
C&CMembersJun 11, 2026, 10:46 (UTC+9)Dutch VPS and Borrowed ISP Relays Power Ranapama Infostealer C2
A Let's Encrypt certificate minted on 29 January 2026 for the domain aceinco.com — valid for exactly 89 days, hosted on a LeaseWeb Netherlands VPS at 85.17.31.111 (AS60781) — is the clearest fingerprint of operator-controlled infrastructure in a 57-IP command-and-control network assembled around the ranapama infostealer. Everything else in the observable pool appears to be borrowed: compromised Korea Telecom broadband endpoints, hijacked subscriber lines on a Belarusian mobile carrier, and at…
#ranapama#infostealer#commandandcontrol#LeaseWeb#KoreaTelecom#SOHOroutercompromise#credentialharvesting#processinjectionIOCf1 · i57 · d0 · u0MITRE30
C&CMembersJun 10, 2026, 14:56 (UTC+9)Five Unrelated Domains Share One 89-Day Certificate Fingerprint
Five infrastructure nodes with no obvious business relationship to one another — the domains resolvent.net, bvwebdesign.nl, platynum.ch and sjd.se, plus the bare IP 135.125.247.10 — all carry a Let's Encrypt TLS certificate with an identical 89-day validity span, and all five were issued within a six-week window between April 22 and June 8, 2026.
#c2infrastructure#Let'sEncryptcertificateautomation#Netskyworm#domainreactivation#TLScertificatefingerprinting#resellerhostingabuse#threatintelligencefeed#SMTPmass-mailerIOCf11 · i7 · d5 · u0MITRE22RegionsNZ
C&CMembersJun 10, 2026, 13:03 (UTC+9)Phorpiex Swaps Three Payloads While C2 Infrastructure Holds Firm
Three new PE32 executables have entered the Phorpiex botnet's active file set while three prior payloads were simultaneously retired — a clean swap that leaves the campaign's command-and-control backbone untouched for the eighth consecutive observation window. The rotation is surgical: the two C2 IP addresses, the wildcard certificate architecture anchored to *.certsdom.com, and the staging URL pattern under tsrv2.top all persist unchanged, while the operator pushes fresh binaries through the…
#Phorpiex#emailworm#botnet#Pakistan#telecommunications#payloadrotation#C2infrastructure#sandboxevasionIOCf3 · i2 · d0 · u4MITRE33RegionsPKIndustriesTelecommunications
C&CMembersJun 10, 2026, 08:09 (UTC+9)A Five-Year-Old Phorpiex Dropper Still Wears a Windows Disguise
A Phorpiex dropper compiled on 31 October 2020 is still being flagged by anti-malware engines today, and it hasn't needed a rewrite to stay useful. The sample (tracked internally as 5d9b6c49a8c8…) presents itself under the names DriveMgr.exe and C:\2994616913505\svchost.exe — masquerading as ordinary Windows plumbing [T1036] rather than anything a user would think twice about.
#Phorpiex#ClipBanker#Botx#sandboxevasion#C2infrastructure#wildcardTLScertificate#cryptocurrencyclipboardhijacking#MexicogovernmentsectorIOCf3 · i1 · d2 · u11MITRE34RegionsMXIndustriesGovernment
C&CMembersJun 10, 2026, 06:49 (UTC+9)LummaStealer Adds Isolated .qpon Node and 20 Hashes as Proton66 Cluster Holds
Since CTX Team's earlier coverage of this LummaStealer campaign, the operator has added twenty new file hashes to the payload catalog and provisioned a structurally distinct second domain — recenjc.qpon — that sits entirely outside the tight infrastructure cohort binding the original eight command-and-control nodes. The earlier coverage documented a remarkably coherent C2 fabric: eight pseudo-random seven-character hostnames under the Soviet-era .su TLD, all batch-registered on a single day,…
#LummaStealer#Proton66#C2infrastructure#credentialtheft#Spain#bulletproofhosting#malware-as-a-service#TraefikmisconfigurationIOCf20 · i1 · d9 · u17MITRE38RegionsES
C&CMembersJun 9, 2026, 19:37 (UTC+9)Dual-TLD DGA Gives Kazakhstan Ransomware Campaign Sinkhole-Resistant C2
Eighteen command-and-control domains generated by a single deterministic algorithm — split evenly across .ru and .su top-level domains, each carrying an identical 15-character vowel-heavy label structure — form the backbone of a financially motivated ransomware-adjacent campaign targeting Kazakhstan. The architecture is deliberate: by producing parallel domain sets from a common seed, the operator has engineered a C2 layer where sinkholing the .ru cluster leaves the structurally identical .su…
#trojan.bitmin/razy#domaingenerationalgorithm#Kazakhstan#dual-TLDC2#UPXpacking#TLSmasquerade#removablemediapropagation#ransomwareIOCf3 · i2 · d18 · u20MITRE39RegionsKZ