logo

Hunt.io Insights: Gamaredon’s Flux-Like Infrastructure and a Look at Recent ShadowPad Activity

ID: 595dda9e-8384-52dc-916a-249862af797a

STIX ID: report--595dda9e-8384-52dc-916a-249862af797a

Feed Name: Hunt.io Blog

Threat Score
86/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This Hunt.io intelligence brief describes two distinct clusters of internet-facing infrastructure linked to state-sponsored actors: Gamaredon (Russian-linked) using low-frequency fast-flux DNS patterns across many .ru domains and a separate cluster with reused spoofed TLS certificates and a ShadowPad backdoor (Dvx.zip) showing overlaps with RedFoxtrot. The report details observed TTPs—short DNS TTLs, wildcard A records, DLL side-loading, dynamic DNS abuse, and certificate reuse—and provides extensive IOCs (IP addresses, domains, and file hashes) to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.