logo

A Multi-Actor Infrastructure Investigation

ID: 28a1bdaf-8292-55a9-8380-55b062c0c8e8

STIX ID: report--28a1bdaf-8292-55a9-8380-55b062c0c8e8

Feed Name: IntelInsights (Substack)

Threat Score
72/100

Date Published: 2024-12-11

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report maps a large, likely shared criminal infrastructure supporting infostealers (LummaC2, Rhadamanthys) and AsyncRAT, centered on C2 154.216.20.204 and expanding via file-hash communications to numerous IPs across multiple ASNs. It notes Cloudflare reverse proxy usage to mask backends, unusual SSH configurations on Wowrack infrastructure, and further pivots (e.g., geolocation API HTML titles) revealing additional malicious servers. The document provides a consolidated list of IOCs (hashes and IPs), assessing moderate-to-high confidence that multiple threat actors are leveraging this ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.