Threat Intelligence Dossier: TOXICSNAKE
Essential information
- Published
- 30/01/2026 08:44
- Modified
- 30/01/2026 08:52
- Tags
- 2026-01-30 bulletproof hosting burner-domains cybercrime infrastructure analysis javascript loader obfuscation osint tds
- Related entities
- 3 observables, 4 techniques (mitre), 6 others
Description
A multi-domain traffic distribution system (TDS) operation was discovered, centered around the domain toxicsnake-wifes.com. The infrastructure serves as a commodity cybercrime TDS farm, routing victims to phishing, scams, or malware payloads. The operation uses a first-stage JavaScript loader, followed by a second-stage that attempts to fetch upstream payloads. The cluster shares common WHOIS, DNS, and hosting patterns, indicative of bulletproof VPS usage. Multiple burner domains with similar tradecraft were identified, suggesting an organized operator cluster. The infrastructure employs obfuscation, dynamic remote injection, and disposable registration techniques. While the main payload was unreachable during analysis, historical evidence suggests the delivery of malicious content.