Skip to content

A Day In Cybercrime: May 20, 2026

Kirk
5 min read
threat-intelc2ransomwareinfrastructuresupply-chaindns
On this page

News

Microsoft released a mitigation for YellowKey (CVE-2026-45585), a BitLocker bypass vulnerability that was publicly disclosed last week. The Hacker News (opens in new tab)

GitHub confirmed 3,800 internal repositories were breached after an employee installed a malicious VS Code extension. Bleeping Computer (opens in new tab)

A new Shai-Hulud supply-chain wave published more than 600 malicious npm packages. Bleeping Computer (opens in new tab)

Developer workstations are now squarely part of the software supply chain. Package registries and CI pipelines matter, but the SSH keys, PATs, and tokens sitting on local machines are still an entry path. The Hacker News (opens in new tab)

Microsoft also confirmed non-dismissible Teams location prompts on macOS after a macOS update. Bleeping Computer (opens in new tab)

Ransomware Claims

14 claims posted across 9 groups, covering 11 countries and 5 sectors over the past 24 hours.

Most active groups: Krybit (3), Nova (2), Dragonforce (2), Akira (2).

Targeted sectors: Business Services (4), Manufacturing (3), Technology (1), Education (1), Financial Services (1).

Countries hit: PL (2), AT (2), ES, TW, CY, US, GB, DE, and several others.

C2 Observations

1,242 family-host pairs were observed in the last 24 hours, spanning 159 malware families across 561 unique C2 hosts. Top families by C2 count:

FamilyC2 Endpoints
AsyncRAT149
Remcos80
NanoCore63
Quasar63
XWorm60
Remus Stealer47
Vidar36
RedLine29
Cobalt Strike28
Remus26
SmokeLoader26
DonutLoader23

Shared Hosts

Several infrastructure hosts served as concentration points for multiple malware families.

HostFamiliesAS / Country
176[.]46[.]152[.]4663 family labels, including Amadey, Cobalt Strike, Lumma, NanoCore, Quasar, Remcos, RedLine, SmokeLoader, Vidar, XWormFarahoosh Dena PLC, IR
api[.]telegram[.]org51 family labels, including AgentTesla, Amadey, AsyncRAT, Cobalt Strike, DonutLoader, Quasar, RedLine, Remcos, Vidar, XWormTelegram Messenger Inc, VG
193[.]161[.]193[.]9948 family labels, including Amadey, AsyncRAT, Cobalt Strike, Lumma, Quasar, RedLine, Remcos, Vidar, XWormOOO GETWIFI, RU
5[.]101[.]82[.]440 family labels, including Amadey, AsyncRAT, Cobalt Strike, DonutLoader, Quasar, RedLine, Remcos, Vidar, XWormGTHost, US
51[.]77[.]77[.]16134 family labels, including Amadey, AsyncRAT, Cobalt Strike, Dragonforce, Quasar, RedLine, StealC, Vidar, XWormOVH SAS, FR

Quad9 DNS Activity

25 of the 561 unique C2 hosts triggered Quad9 blocking in the past 24 hours.

Top 10 New Quad9 C2 Blocks (24hour)

HostFamiliesBlocked C2 eventsTop countries
sunwin[.]keQuasar2,357VN, DE, US, GB, CH
69sexy[.]duckdns[.]orgMirai1,746DE, AT, US, NZ, GH
f****er1[.]duckdns[.]orgMirai1,546DE, US, SE, IE, NL
popit[.]ioAsyncRAT, NanoCore1,354US, VN, FR, RU, CH
doctopus[.]ioAsyncRAT1,230US, DE, BR, FR, SG
honeypotresearchteam[.]duckdns[.]orgRemcos1,004BH, JO, IN, US
qtumeco[.]ioAsyncRAT979US, ES, CH, FR, RU
www[.]echodex[.]ioAsyncRAT733US, FR, DE, VN, NL
component-warehouse[.]co[.]ukAsyncRAT715VN, US, CH, RU, DE
kolt[.]ioAsyncRAT598US, IN, FR, CH, RU

Top 10 All C2 DB Quad9 C2 Blocks (24hour)

HostBlocked C2 eventsTop countries
ff[.]vvbb321[.]com413,137DE, US
ff[.]aass654[.]com413,132DE, US
ff[.]nnmm234[.]com413,126DE
ff[.]jjkk567[.]com413,121DE, US
ff[.]xxcc789[.]com413,119DE, US
hh[.]jjkk567[.]com357,727LK, IN, US, RU
hh[.]nnmm234[.]com357,721LK, CH, RU, US
hh[.]aass654[.]com357,719LK, US, CH, RU
hh[.]xxcc789[.]com357,716LK, IN, US
cc[.]nnmm234[.]com134,176US

Infrastructure

561 unique C2 hosts mapped across 37 countries, 151 providers, and 5 infrastructure types.

ProviderC2 hosts
Cloudflare184
DigitalOcean36
Alibaba Advertising17
Amazon12
Great Flower11
Hetzner11
Omegatech11
unknown10
OOO GETWIFI8
Google7

The US led with 309 C2 hosts, followed by China at 35, Germany at 31, the UK at 24, and Russia at 23. Hosting carried 484 hosts, ISP space held 52, unknown infrastructure held 10, business networks held 9, and sinkholes held 6.

Latest From Derp

Share this article