Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed
ID: 28eebb22-360e-569f-8194-2b0698e6c58a
STIX ID: report--28eebb22-360e-569f-8194-2b0698e6c58a
Feed Name: cybersecurityNews.com
Security researchers uncovered a coordinated cybercrime campaign using education-branded domains as a traffic distribution system (TDS) named TOXICSNAKE to deliver obfuscated JavaScript loaders that route victims to malware, phishing pages, and scams. The report details multiple malicious domains, infrastructure characteristics (HZ Hosting Ltd ASN AS202015, 185.33.84.0/23 netblock, Regway nameservers), and evasion techniques including per-visitor tokenization, dedicated IP addressing per domain, automated Let’s Encrypt certificates, and disposable WHOIS, while noting researchers recovered a loader but observed HTTP 504 responses from upstream payload servers during analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
