Play it!
ID: d0e96383-69e5-54f3-b03f-fd1f483909f4
STIX ID: report--d0e96383-69e5-54f3-b03f-fd1f483909f4
Feed Name: IntelInsights (Substack)
This report analyzes a C2 URL that pivots to infrastructure abusing the legitimate playit.gg tunneling service (AS40519), identifying numerous domains and IPs that redirect to playit.gg and are associated with malware activity (e.g., njRAT, XWorm). Using passive DNS, Censys, and Shodan pivots, it enumerates IOCs and shows how threat actors exploit playit.gg’s CDN/reputation to host malicious and phishing domains and conceal C2 traffic, indicating ongoing multi-actor cybercrime operations leveraging this platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
