216.73.217.22

Threat Intelligence Dossier: TOXICSNAKE

· Published 30/01/2026 08:44 · Modified 30/01/2026 08:52

Export JSON

Essential information

Published
30/01/2026 08:44
Modified
30/01/2026 08:52
Tags
2026-01-30 bulletproof hosting burner-domains cybercrime infrastructure analysis javascript loader obfuscation osint tds
Related entities
3 observables, 4 techniques (mitre), 6 others

Description

A multi-domain traffic distribution system () operation was discovered, centered around the domain toxicsnake-wifes.com. The infrastructure serves as a commodity farm, routing victims to phishing, scams, or malware payloads. The operation uses a first-stage , followed by a second-stage that attempts to fetch upstream payloads. The cluster shares common WHOIS, DNS, and hosting patterns, indicative of bulletproof VPS usage. Multiple burner domains with similar tradecraft were identified, suggesting an organized operator cluster. The infrastructure employs , dynamic remote injection, and disposable registration techniques. While the main payload was unreachable during analysis, historical evidence suggests the delivery of malicious content.

External references