logo

Keeping up with the Infostealers

ID: ea68adc3-db28-54e0-a717-45bdfcaa619a

STIX ID: report--ea68adc3-db28-54e0-a717-45bdfcaa619a

Feed Name: IntelInsights (Substack)

Threat Score
70/100

Date Published: 2025-01-28

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

Research maps active infostealer-related infrastructure starting from 185.215.113.16 (AS51381/1337team Limited) using Censys queries (ports 22 and 80) and pivots via SSH/certificate fingerprints and a related malicious file (“cajubae”), uncovering 20 hosts tied to Amadey/Smoke loaders and infostealers (Redline, Lumma, MarsStealer, Stealc), plus newly identified IP clusters in Korea (notably AS3786, AS4766) and Mexico; the domain niksplus.ru shows fast-flux behavior, and the post provides extensive IP-based IoCs indicating recently deployed malicious infrastructure likely supporting ongoing infostealer activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.