Skip to content
Cybercriminals Shift Domains, Maintain Malware Hosting Networks

Cybercriminals Shift Domains, Maintain Malware Hosting Networks

First seen 24 Sep 2026, 09:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 09:56 UTC
  • Cybercriminals are using a stable hosting network while frequently changing lure domains.
  • The ClickFix technique employs social engineering to execute commands on victims' machines.
  • Static IP blocklists are becoming ineffective against these evolving malware campaigns.

Cybercriminals are rapidly rotating lure domains and command-and-control channels while maintaining a stable bulletproof hosting network, AS202412, operated by OMEGATECH LTD. Over five months, researchers identified four distinct malware delivery chains linked to this network, highlighting the difficulty of blocking individual domains. The initial access method, ClickFix, uses social engineering to trick victims into executing malicious commands via the Windows Run dialog. This technique circumvents traditional defenses focused on file downloads and suspicious links. The observed lure domains often feature predictable naming patterns, allowing attackers to quickly switch to new domains without significant cost. The infrastructure's resilience poses a growing challenge for cybersecurity defenses, as static IP blocklists become less effective due to frequent changes in address space.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-04-24
Monitoring of malware delivery chains begins
Researchers started tracking malware delivery chains linked to AS202412, identifying multiple attack vectors.
cybernoz.com
2026-09-24
Current monitoring report published
A report detailing the ongoing use of AS202412 for malware delivery was published, emphasizing the challenges of blocking individual domains.
Ground.News
2026-09-24
Article published on malware infrastructure
IT Security News published an article reiterating the findings about the persistent malware hosting networks and their implications.
www.itsecuritynews.info

More articles in this cluster (4)

Following this threat?

Track ClickFix and Omegatech LTD in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed