logo

Threat Actors Hide Behind School-Themed Domains In Newly Uncovered Bulletproof Infrastructure

ID: e58b2b1e-4fab-521b-a297-2b33d6986fbf

STIX ID: report--e58b2b1e-4fab-521b-a297-2b33d6986fbf

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Varshini

...
...

Analysts found a sophisticated traffic distribution system (TDS) operating behind education-themed domains that uses a first-stage XOR-obfuscated JavaScript loader (e.g., https://toxicsnake-wifes.com/promise/script.js) to fingerprint and route victims to phishing, scams, and malware payloads; the infrastructure leverages bulletproof hosting (HZ Hosting Ltd, AS202015), disposable Let’s Encrypt certificates, shared WHOIS/contact details, and multiple related domains and IPs (185.33.84.152, 185.33.84.189) indicating an operator cluster distributing credential-stealers and other commodity malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.