logo

DNS Early Detection – Breaking the CoralRaider Kill Chain

ID: cf775c04-94a5-560c-a7aa-30ebcb36cdf1

STIX ID: report--cf775c04-94a5-560c-a7aa-30ebcb36cdf1

Feed Name: Infoblox Threat Intel Blog

Threat Score
70/100

Date Published: 2024-07-02

Date Updated: 2026-04-28

Author: Michael Zuckerman

...
...

Infoblox details the CoralRaider campaign (active since Feb 2024) that delivers info‑stealer malware families — including Rhadamanthys, Lumma C2, and Cryptbot — using CDN-hosted payloads and DNS-based command-and-control; the report enumerates malicious domains observed, documents that Infoblox flagged 94.12% of those domains as SUSPICIOUS (on average ~76.8 days before OSINT), and recommends using Infoblox suspicious-domain feeds to automatically block the infrastructure and disrupt the kill chain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.