logo

Russian registrar NAUNET knowingly harbours Cybercriminals

ID: 2efb7ea7-969b-56ad-9a99-8888436c747a

STIX ID: report--2efb7ea7-969b-56ad-9a99-8888436c747a

Feed Name: The Spamhaus Project

Threat Score
75/100

Date Published: 2012-03-22

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

Spamhaus reports an active Feodo banking-Trojan campaign using DGA-generated .ru domains registered via the NAUNET registrar and supported by a fast-flux network of hijacked servers and rotating IPs. The report includes sample C2 HTTP traffic, DNS/NS anomalies, a table of associated IPs (many on blocklists) and a long list of malicious domains, and documents NAUNET's refusal to suspend these domains while recommending networks block or blacklist NAUNET's address space.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.