logo

Play it!

ID: d0e96383-69e5-54f3-b03f-fd1f483909f4

STIX ID: report--d0e96383-69e5-54f3-b03f-fd1f483909f4

Feed Name: IntelInsights (Substack)

Threat Score
70/100

Date Published: 2024-12-07

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

This report analyzes a C2 URL that pivots to infrastructure abusing the legitimate playit.gg tunneling service (AS40519), identifying numerous domains and IPs that redirect to playit.gg and are associated with malware activity (e.g., njRAT, XWorm). Using passive DNS, Censys, and Shodan pivots, it enumerates IOCs and shows how threat actors exploit playit.gg’s CDN/reputation to host malicious and phishing domains and conceal C2 traffic, indicating ongoing multi-actor cybercrime operations leveraging this platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.