A Multi-Actor Infrastructure Investigation
ID: 28a1bdaf-8292-55a9-8380-55b062c0c8e8
STIX ID: report--28a1bdaf-8292-55a9-8380-55b062c0c8e8
Feed Name: IntelInsights (Substack)
The report maps a large, likely shared criminal infrastructure supporting infostealers (LummaC2, Rhadamanthys) and AsyncRAT, centered on C2 154.216.20.204 and expanding via file-hash communications to numerous IPs across multiple ASNs. It notes Cloudflare reverse proxy usage to mask backends, unusual SSH configurations on Wowrack infrastructure, and further pivots (e.g., geolocation API HTML titles) revealing additional malicious servers. The document provides a consolidated list of IOCs (hashes and IPs), assessing moderate-to-high confidence that multiple threat actors are leveraging this ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
