logo

A Multi-Actor Infrastructure Investigation (Mapping the Malware Maze)

ID: 793fc620-6ab0-5bde-845b-d329fa4f6883

STIX ID: report--793fc620-6ab0-5bde-845b-d329fa4f6883

Feed Name: infostealers.com

Threat Score
70/100

Date Published: 2024-12-21

Date Updated: 2026-04-28

Author: InfoStealers

...
...

This intelligence write-up details an infrastructure hunt that identifies a cluster of C2 servers and many associated malicious file hashes tied to infostealers and RATs. Key findings include C2 IP 154.216.20.204, numerous communicating IPs (including Cloudflare-backed and Wowrack hosts), evidence of AsyncRAT activity, SSH fingerprint pivots that link additional hosts, and a compiled IOC list of IPs and hashes; the author concludes the infrastructure is widely used by multiple actors to serve infostealers and RATs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.