IntroductionThe modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligen
The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks.
Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.
To construct these networks, adversaries systematically compromise unpatched, end-of-life devices. By targeting legacy, unpatched Small Office/Home Office (SOHO) router and Internet-of-Things (IoT) devices attackers can create a sprawling, decentralised mesh of proxy nodes. By routing their operations through layers of compromised devices, adversaries mask their true origins, making malicious activity blend seamlessly with legitimate regional traffic.
Blogs by my colleagues at Team Cymru as well as Google offer detailed explanations as to why and how these ORBs have grown over many years and continue to expand.
Project Background
Project ORBITAL represents a centralised Open Source Intelligence (OSINT) collection driven by public reporting from advanced research teams across the cybersecurity and technology sectors. This initiative aggregates telemetry and findings from top-tier vendors including Cisco Talos, CrowdStrike, Google, GreyNoise Labs, Lumen Black Lotus Labs, Microsoft, SecurityScorecard, Sekoia, SentinelLabs, Sygnia, and Team Cymru. Furthermore, it incorporates critical alerts and intelligence shared publicly by United States government agencies, specifically the Federal Bureau of Investigation (FBI), the Cyber National Mission Force (CNMF), and the National Security Agency (NSA).
This repository builds on the methodology of my previous OSINT tracking initiatives. It is heavily inspired by the structure and community success of my earlier matrix projects, specifically the Ransomware Tool Matrix (RTM) (here), the Ransomware Vulnerability Matrix (RVM) (here), and the Russian APT Tool Matrix (RUTM) (here). By applying a similar, structured approach to mapping Operational Relay Box (ORB) networks, this project aims to provide defenders with a clear, actionable lexicon for hunting and tracking evasive edge-device botnets.
Graph Visualisation
Once Project ORBITAL was initially assembled, it was then possible to use a GitHub Action automation with NetworkX and PyVis to create a Graph Visualisation using the data collected. Once in this view, some interesting patterns could be observed.
Analysis of the extracted data uncovered that ASUS devices were the most targeted out of all of the targeted devices by ORBs from the public reports.
Another interesting point the graph highlighted is that the LapDogs ORB network had the highest number of reported targeted devices.
In most reported scenarios, a singular threat group used a dedicated ORB network. However, from extracting the details from the Google and SentinelLabs reports, an adversary like APT15, reportedly leverages both SPACEHOP and PurpleHaze ORB networks, alongside two other separate adversaries UNC2630 and UNC5174.
The overlap in ORB usage suggests these APTs aren't all building their own botnets from scratch. These overlaps likely indicate there are provisioning teams, such as specialised contractors, like Beijing Integrity Tech, who build and maintain these ORB networks and then lease access to the broader Chinese intelligence community in the Ministry of State Security (MSS) and People’s Liberation Army (PLA).
Panda-monium
Below is the list of well-known China-nexus APTs listed using CrowdStrike’s naming scheme and their Google or Microsoft aliases that are all mentioned in Project ORBITAL.
CAULDRON PANDA (aka UNC3886)
ETHEREAL PANDA (aka Flax Typhoon)
JUDGMENT PANDA (APT31, Violet Typhoon)
KEYHOLE PANDA (aka UNC2630, APT5)
MURKY PANDA (aka Silk Typhoon)
VANGUARD PANDA (aka Volt Typhoon)
VIXEN PANDA (aka APT15, Nylon Typhoon)
The most notable aspect about this list is that it contains APTs with wildly different mandates. VANGUARD PANDA (Volt Typhoon) is famous for pre-positioning within critical infrastructure with the potential disruptive attacks, while KEYHOLE PANDA (APT5) and JUDGMENT PANDA (APT31) are long-running cyber-espionage and IP theft operators. The fact that both the saboteurs and the spies have all adopted ORB networks goes to show that this tactic is not niche but instead is the baseline standard for Chinese APT operational security (OPSEC).
How to Access
You can find Project ORBITAL on my GitHub repository below:
One of the challenges with investigating cybercrime is the
infrastructure the adversaries leverage to conduct attacks. Cybercriminal
infrastructure has evolved drastically over the last 25 years, which now involves
hijacking web services, content distribution networks (CDNs), residential
proxies, fast flux DNS, domain generation algorithms (DGAs), botnets of IoT
devices, the Tor network, and all sorts of nested services.
This blog shall investigate a small UK-based hosting provider
known as Bit
One of the challenges with investigating cybercrime is the
infrastructure the adversaries leverage to conduct attacks. Cybercriminal
infrastructure has evolved drastically over the last 25 years, which now involves
hijacking web services, content distribution networks (CDNs), residential
proxies, fast flux DNS, domain generation algorithms (DGAs), botnets of IoT
devices, the Tor network, and all sorts of nested services.
This blog shall investigate a small UK-based hosting provider
known as BitLaunch as an example of how challenging it can be to tackle
cybercriminal infrastructure. Research into this hosting provider revealed that
they appear to have a multi-year history of cybercriminals using BitLaunch to
host command-and-control (C2) servers via their Anonymous
VPS service.
The year-on-year growing number of CobaltStrike C2 servers
hosted on BitLaunch’s services could be an indicator of tacit collusion with
cybercriminals through the facilitation of cheap and quick to procurement of
VPSs that end up being used to launch ransomware attacks on all sorts of
victims, including hospitals, schools, governments, companies, and charities.
The concept of aiding and abetting criminal activity in law is
essentially when an individual or an organisation intentionally assists,
facilitates, or encourages a crime. In this case, it would be aiding and
abetting the creation of cybercriminal infrastructure. If a hosting provider
ignores clear red flags (e.g., cryptocurrency payments from known illicit
sources or use of servers for illegal activities), they might still be held criminally
liable under wilful blindness under certain laws.
In the past, authorities have taken down bulletproof hosting
(BPH) providers that knowingly support cybercrime, such as CyberBunker and
LolekHost. In February 2025, the UK government also sanctioned
a Russia-based BPH known as ZSERVERS (aka XHOST) for facilitating LockBit
attacks.
Update: This blog was updated with a statement from BitLaunch (see the end of this blog).
Who is BitLaunch aka BL Networks aka BLNWX?
Active since at least 2017, BitLaunch (also known as BL
Networks or BLNWX) is a virtual private server (VPS) reseller whose autonomous
system number (ASN) is AS399629.
Up to 48 IPv4 networks belong to BitLaunch
which are used to "instantly launch a Linux or Windows VPS” where
customers can “pay hourly with Bitcoin, Litecoin, and Ethereum, with no firm
commitments." BitLaunch also supports their customers via a command-line (CLI)
tool and a Python
library. BitLaunch has another name, however, in their legal terms and conditions
they go by Liber Systems and have their own separate website.
Why focus on BitLaunch?
BitLaunch is quite interesting as they present themselves as
a UK-based company run by two local UK businessmen. Their “anonymous Bitcoin
VPS” service is regularly abused for all sorts of cybercriminal activities. What
triggered this research was the fact that their nickname “BLNWX” was regularly
reappearing in cyber threat intelligence (CTI) vendor reports on ransomware and
other cybercriminal campaigns. It is also worth highlighting that while BitLaunch own their
own IP networks, they are a VPS reseller as well who works with DigitalOcean,
Linode, and Vultr, as shown from their website below.
One website that reviews so-called “offshore services” (offshore[.]cat) has listed BitLaunch as being a “verified” offshore hoster that accepts cryptocurrency, only requires email request confirmation to open an account, and is described as allowing anyone to “create VPSs in seconds, using crypto” making them an attractive hoster for cybercriminals. Their service paired with their CLI tools and Python libraries makes it super easy to stand up C2 servers rapidly.
Command and Control (C2) infrastructure on BLNWX
Significant numbers of CobaltStrike C2s among other hacking
tools and malware families have been discovered on BitLaunch. I would like to
thank the owner of the C2IntelFeedsBot (@drb_ra)
account on X/Twitter who assisted with this research by providing their feed of
C2 servers discovered on BitLaunch.
The image below shows a sampling of the known C2 servers
hosted with BitLaunch between 2021 and 2025. The most notable part of this
diagram is the number of CobaltStrike C2 servers in particular. Cobalt Strike
is a well-known C2 framework used by organised cybercriminal groups to launch
ransomware attacks. It is also favoured by state-sponsored threat groups as
well.
Over the last few years, several dozen C2 servers have been
identified by the C2IntelFeedsBot and each
year, the number of C2s has continued to grow as more cybercriminals identify
BitLaunch as a preferable service to support their ransomware campaigns.
The image below displays the totals calculated between “2021-06-26
12:33:41" and "2025-02-05 18:46:10." It is not a complete
picture by any means, but this independently verifiable data gives a decent
idea of the rate at which BitLaunch is being used by cybercriminals, with each
year since 2022 has trended upwards.
One of the interesting things about CobaltStrike is that it
is a commercial offensive security tool (OST). It is issued to legitimate
customers through licenses, which have a unique watermark. While there have
been several cracked versions of CobaltStrike over the years, it is possible to
track certain groups through their usage of the same CobaltStrike versions.
The image below shows the distribution of the CobaltStrike
watermarks gathered from BitLaunch. Notably, “0” is the most common. This is
often the case when analysing CobaltStrike watermarks as this signifies it is
the cracked version.
OSINT collection and analysis of the CobaltStrike watermarks
revealed potential connections to several well-known cybercriminal groups using
BitLaunch who have a history of conducting ransomware attacks:
"426352781” – This watermark is used by ShadowSyndicate,
a ransomware affiliate group tracked by Group-IB which is connected to multiple
Ransomware-as-a-Serivce (Raas) platforms. This watermark is also historically associated
with CobaltStrike Beacons dropped
by the Qakbot malware botnet.
“1580103824” – This watermark was linked to ShadowSyndicate
as well, alongside the Cleo
exploitation campaign attributed CL0P ransomware. A threat group tracked by
CERT-UA as UAC-0056 has also been observed
using this watermark too.
”987654321” – This watermark has been associated
with the IcedID malware botnet and the Dagon Locker ransomware gang previously.
”1359593325” – This watermark has been used by CobaltStrike
Beacons in campaigns attributed
to the Russian Foreign Intelligence Service (SVR)
“391144938” and “305419896” – These watermarks have been
attributed to campaigns by multiple Chinese cyber-espionage campaigns tracked
by SentinelOne,
Recorded
Future, Zscaler,
and Cisco
Talos.
C2s on BLNWX attributed to Ransomware Gangs by CTI vendors
There are a number of CTI reports over the last couple years
that directly reference BitLaunch Networks (BLNWX) IP addresses as Indicators
of Compromise (IOCs) as part of high-profile ransomware campaigns.
This includes attribution
to the Yanluowang ransomware attack against Cisco, a C2 linked
to the JavaScript more_eggs backdoor used by FIN6 (who is connected to
ransomware campaigns), a dozen IPs attributed to Rhysida
ransomware attacks, and a Rhysida and Interlock ransomware precursor
campaign tracked as TAG-124,
as well as the PaperCut
exploitation campaign which involved
both LockBit and CL0P.
Additional notable CTI alerts that called out BLNWX include
a report on Latrodectus,
a ransomware precursor campaign, by Proofpoint; Okta-themed phishing campaigns
attributed to Scattered
Spider, who has carried out ALPHV/BlackCat and RansomHub attacks, by
Intel471; infrastructure used to enable
the BlackBasta ransomware gang by QuadrantSec, as well as C2 servers of the IcedID
malware botnet that has been used by ransomware gangs for initial access.
Assessment of BitLaunch
As of February 2025, BitLaunch's parent firm Liber Systems Limited is run by two UK-based directors according to UK Companies House. While they are profiting off this Anonymous VPS service they are not taking the appropriate steps to prevent their service from being used by
ransomware and malware gangs. Organised cybercrime groups have evidently found and recognised this about BitLaunch and are leveraging the cheap, crypto-accepting service
that doesn’t ask too many questions.
To be fair to BitLaunch, they appear to be responsive to
takedowns and are noted on Offshore[.]cat as enforcing DMCA requests. The crux
of the issue though is that the cybercriminals can use their service to rapidly
spin up instances for C2 for a few hours and chuck it away again. This means there often no need to submit a takedown as the cybercriminals has already abandoned the C2 and can spin up another one. Therefore,
the cybercriminals can continually leverage BitLaunch without interference.
As a security researcher, and not a police officer, I cannot comment on how cooperative BitLaunch have been with the police and it is probably not something BitLaunch would want to advertise to their customers anyway based on who some of their customers are.
For BitLaunch’s two directors, this works out nicely for them. They
can take the cybercriminals money via cryptocurrency and also appear to be
ethical and compliant by assisting with law enforcement takedown requests. Currently, they appear to be helping both the criminals and the police, and have been getting away with it for years.
On BitLaunch’s front page advertisement they highlight as
the main focus as being able to pay hourly for the use VPS and that customers
can pay in “anonymous cryptocurrency.” It is in my opinion, and that of other
cybersecurity researchers I have spoken to about this (including red teamers and penetration testers), that
this service is perfect for C2 servers and almost nothing else legitimate.
The Broader Issue with Anonymous VPSs
In BitLaunch’s blogs, they say they believe the internet should be "open, free, and devoid of interference by any single government or authority" adding that accept cryptocurrency because "citizens of some countries do not have bank accounts and can use Bitcoin
instead" because the local banks have control over who their citizens can send money to.
Their blogs also state that they believe internet users should be allowed to
run their own virtual private networks (VPNs) for anti-surveillance and privacy
reasons. They also provide lots of guides on how to configure private VPNs for this purpose. While this is a legitimate service that is useful for some people in specific situations, having it be abused by ransomware gangs is a situation that needs to be changed.
This issue of selling anonymous VPSs is not specific to this one company. BitLaunch is
obviously a small company and proactively combating cybercriminals from
registering VPSs on their service is an expensive and multi-pronged challenge
for any hoster, which includes preventing abuse while preserving the privacy of
their customers.
Hosters such as BitLaunch could use services such as Shodan, Abuse.ch,
GreyNoise, OTX Alienvault, and AbuseIPDB to check if their IP addresses are
being abused. One interesting example of a hoster trying to tackle this issue is how PQ Hosting (aka Stark Industries Solutions) announced publicly on their blog that they have partnered with Team Cymru, a netflow security intelligence firm. Alternatively, hosters could use a blockchain analytics platform like Chainalysis, TRM Labs, or Arkham Intelligence, to trace cryptocurrency payments from known illicit wallet clusters.
There will, however, always be some threats that slip through the net. It is undoubtedly a difficult challenge for small hosters
who do not have funds to sacrifice on network observability tools or CTI
platforms. Even some of the world’s largest hosters, such as Cloudflare
struggle with this as well and end up having their services abused for cybercrime operations.
The anonymous VPS problem could be
compared to issues in other industries such as stolen funds being used to buy gift cards or game keys that are then resold for money laundering. Another platform often
abused for a variety of scams and phishing campaigns is Gmail. Is Google being
wilfully negligent to cybercrime happening on their platform? That’s a question
I shall leave for readers to decide on their own.
Overall, this type of issue is analogous to a hotel offering rooms for the night and organized criminals renting them to commit various types of crimes inside them. Ultimately, the criminals are the ones breaking the law, not the hotel, but if the hotel is being constantly made aware of these activities by bystanders and law enforcement, it is their duty to shut that activity down, to the best of their abilities.
What the UK Could Do About It
In this scenario around BitLaunch, there are three potential ways the UK could help stop these small hosters being taken advantage of by
cybercriminal operations.
Firstly, the cybersecurity and hosting industry could launch an initiative through institutions, such as the British Computer Society (BCS) or something, that would work to convince hosting providers that the
hassle being investigated by law enforcement agencies, sanctions, or the chance
of being arrested is not worth the funds generated from selling C2 servers to cybercriminals.
Secondly, as BitLaunch (or Liber Systems) is registered here, the UK Government Department for Science, Innovation, and Technology (DSIT) could work with them and other small hosters to regulate the industry and
provide support to these businesses to warn them of the dangers of offering
unregulated VPS services and inform them how they contribute to the
damage that ransomware attacks are having on the UK and elsewhere.
Third, providing free network observability services to
hosters could also help them proactively shutdown C2 servers before they are
weaponised against victims. All UK hosters can sign-up to the free UK
government-provided service called MyNCSC, offered by the UK
NCSC, which is part of GCHQ. Hosters will then get alerts when MyNCSC detects
which IPs are flagged for hosting C2 servers (such as CobaltStrike).
As the UK government’s mandate
is to “make the UK the safest place in the world to live and work online” then
tackling the issue with these UK-based hosters supporting ransomware
should also be one of those priorities.
Indicators of Compromise
Historic Malicious BLNWX IP addresses are available below:
Statement from BitLaunch following the publication of this blog:
"BitLaunch appreciates the conversation surrounding the misuse of VPS hosting services. It is an important topic, and there is always room for improvement and reflection. That said, we believe the article contains several key inaccuracies and misleading implications. We take the prevention of abuse on our platform very seriously, and we would like to offer the following context:
We reject the notion that BitLaunch may be in "tacit collusion with cybercriminals" due to the year-on-year growth of IPs associated with CobaltStrike C2 servers. In fact, the number of abusive IPs has not increased relative to BitLaunch's rapid infrastructure growth – it is just that more IP blocks are available overall.
At the time of writing, BitLaunch has 50 /24 prefixes announced over BGP, totalling 12,800 IP addresses. As a result, 82 C2s in 2024 represents just 0.6% of our IPs over the entire year. Across all first and third party hosts, abuse per month is around 1% of active servers.
We strongly disagree that BitLaunch is "not taking the appropriate steps to prevent their service from being used by ransomware and malware gangs". BitLaunch takes regular and concrete action against abuse, including no longer serving the Russian market. We employ a full-time, dedicated abuse team that already uses various tools to proactively and passively identify malicious servers. These tools include abuse.ch, urlscan, spamhaus, and more. Servers are suspended as soon as malicious activity is suspected, per our Acceptable Use policy.
The report implies that BitLaunch may be ignoring key red flags, such as accepting cryptocurrency from known illicit sources, and mentions that hosters can use blockchain analysis services to prevent this. BitLaunch already uses Elliptic for this purpose. We also disagree with the opinion that our service is "perfect for C2 servers and almost nothing else". As previously stated, abuse per month accounts for 1% of active servers despite BitLaunch accepting payments exclusively in cryptocurrency. There are numerous reasons to pay privately with cryptocurrency that do not involve illegal activity.
We believe the report fails to disclose a potential conflict of interest. The researcher works for Carrier Hotel Equinix, which serves some of our direct competitors. One such customer, PQ Hosting, is linked in the blog as a positive example of dealing with malicious activity.
Finally, we would like to thank BushidoToken for giving us a chance to issue this addendum. We welcome constructive critique on this topic and appreciate the opportunity to reflect on our abuse-prevention strategies and their communication."
Introduction to Infrastructure Pivoting
Pivoting on infrastructure is a handy skill for cyber threat
intelligence (CTI) analysts to learn. It can help to reveal the bigger picture
when it comes to malware, phishing, or network exploitation campaigns. Infrastructure
pivoting essentially is the act of looking for more systems an adversary has
created. The main benefit of this pursuit is the identification of additional
targets or victims, more tools or malware samples, and ultimately new insigh
Pivoting on infrastructure is a handy skill for cyber threat
intelligence (CTI) analysts to learn. It can help to reveal the bigger picture
when it comes to malware, phishing, or network exploitation campaigns. Infrastructure
pivoting essentially is the act of looking for more systems an adversary has
created. The main benefit of this pursuit is the identification of additional
targets or victims, more tools or malware samples, and ultimately new insights
about the adversary’s capabilities.
If done correctly, being able to pivot on adversary
infrastructure will be very useful during incident response (IR) engagements. For
example, it may lead to being able to attribute the intrusion to a known
adversary. This will help others during an IR engagement understand the level
of threat posed to the victim organisation.
Receiving Threat Data
To be able to pivot on adversary infrastructure, threat data
is needed such as the intelligence shared by threat reports put out
by various researchers from public and private sector organisations. This
scenario, however, involves relying on the analysis skills of other researchers to explain
what the infrastructure is and when they observed it in use.
This blog will examine threat data provided by public sector
organisations such as the Computer Emergency Response Team of Ukraine (CERT-UA)
as well as cybersecurity vendors such as Deep Instinct, Cyble, and Fortinet.
These organisations have shared indicators of compromise (IOCs) uncovered
following analysis of adversary intrusion activities or upload to online
malware sandboxes, such as VirusTotal, among others.
Introduction to the Ghostwriter Campaign
On 3 June 2024, Fortinet shared a report
on malicious XLS macro documents leading to Cobalt Strike Beacons. Analysis of
the XLS documents showed that they appeared to be targeting the Ukrainian
military and linked to a known Belarusian state-sponsored APT group tracked as Ghostwriter
(aka UNC1151, UAC-0057, TA445). On 4 June 2024, Cyble also shared a report
on a similar campaign.
In both reports, if the XLS was opened and the macros were executed
by the target, a malicious DLL file was downloaded from an adversary-created domain.
In Fortinet’s report, two similar “.shop” domains were mentioned. In Cyble’s
report another “.shop” domain was also called out.
Overlapping IOCs
The first pivot on Ghostwriter APT infrastructure that will be
demonstrated involves finding indicators of compromise (IOCs) such as domains
and IP addresses that appear in multiple threat reports.
The fastest way to realize these overlaps is through
continuous collection of reported IOCs into a Threat Intelligence Platform
(TIP). This will reveal IOCs that appear in multiple threat reports through
tagging and sources of where IOCs come from. Eventually, one domain or IP
address will get reported by multiple entities and the connection will make
itself apparent.
In Figure 1 (see below) the domain “goudieelectric[.]shop”
appeared in both Cyble’s blog and Fortinet’s blog. Analysis of all three
domains found that they use the same generic top-level domain (gTLD),
registrar, and name servers, as well as have a robots.txt directory configured.
These common infrastructure characteristics indicate that all three domains
were created by the same adversary.
Figure 1. Three similar
domains appearing in two threat reports.
Domain Registration & Hosting Overlaps
When more IOCs are reported in other threat reports it is
possible to link them to other known domains, this is due to adversaries
reusing the same registrars, name servers, and gTLDs.
In Figure 2 (see below), Deep Instinct reported
two more domains that could also be linked to the previous three domains through
the mutual use of the PublicDomainsRegistry registrar, Cloudflare name servers,
and the robots.txt file.
Figure 2. Five
similar domains that appear across three threat reports.
Further, CERT-UA reported three more domains (see
Figure 3 below) that could be linked to the infrastructure cluster through this
same method as well. This pattern of behaviour is a strong indicator that these
domains were created by the same adversary.
Figure 3. Eight similar domains that appear across four threat reports.
Finding Unreported Domains
Since the domains from the above threat reports were
collected and linked together through overlapping attributes, it is now
possible to use these attributes to find more domains that had gone unreported.
Using a VirusTotal domain attribute query, additional domains
can be found by using the following registration pattern:
Name Servers: CLOUDFLARE
Registrar: PublicDomainRegistry
TLD: *.shop
This revealed up to 24 domains that matched this pattern
that were likely created by Ghostwriter, a state-sponsored APT group:
backstagemerch[.]shop
bryndonovan[.]shop
chaptercheats[.]shop
clairedeco[.]shop
connecticutchildrens[.]shop
disneyfoodblog[.]shop
eartheclipse[.]shop
empoweringparents[.]shop
foampartyhats[.]shop
goudieelectric[.]shop
ikitas[.]shop
jackbenimblekids[.]shop
kingarthurbaking[.]shop
lansdownecentre[.]shop
lauramcinerney[.]shop
medicalnewstoday[.]shop
moonlightmixes[.]shop
penandthepad[.]shop
physio-pedia[.]shop
semanticscholar[.]shop
simonandschuster[.]shop
thevegan8[.]shop
twisterplussize[.]shop
utahsadventurefamily[.]shop
Note: VirusTotal domain searches are only available
to VirusTotal Enterprise users. There are other providers which allow you to search
for domain registration patterns such as DomainTools, Validin, and Zetalytics. There
also some free OSINT sites such as nslookup.io
and viewdns.info that can be useful in
certain scenarios.
Finding Related Malware Samples
Using the list of similar domains that were uncovered
through the registration pattern search, it is then possible to find additional
malware samples communicating with them.
This can be achieved by looking at domains in VirusTotal and
checking the Relations tab can show communicating files as shown in
Figure 4 below.
Figure 4. Additional malware samples
uncovered via the VirusTotal relations tab
Using a VirusTotal graph can help to reveal every
communicating file with every domain discovered through the registration pattern
search, as shown in Figure 5 below.
Figure 5. All
communicating files with every additional domain identified.
In conclusion, it is important for CTI analysts to closer
inspect the attributes of the IOCs they come across. It is not uncommon for
state-sponsored APT groups to make such mistakes when creating their
infrastructure to launch attacks from. By exploiting this fact, CTI analysts
can learn much more about the adversary’s targets, capabilities, and the behaviours
of the humans themselves behind such campaigns.
The importance of this type of work was demonstrated in
December 2023 when the US Treasury
sanctioned members of the Russian APT group known as Callisto
(aka Star Blizzard, BlueCharlie, COLDRIVER, GOSSAMER BEAR). The real world
identity of Andrey Korinets was revealed after he was sanctioned for fraudulently
creating and registering malicious domain infrastructure for Russian federal
security service (FSB) spear phishing campaigns.