Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed
Security researchers have identified a complex traffic distribution network utilizing deceptive education-themed domains for malware and phishing attacks. This network, associated with infrastructure indicators known as TOXICSNAKE, uses university and…
Security researchers have identified a complex traffic distribution network utilizing deceptive education-themed domains for malware and phishing attacks. This network, associated with infrastructure indicators known as TOXICSNAKE, uses university and educational institution branding to mislead users into accessing malicious websites.
The network exploits user trust in educational platforms, serving as an effective social engineering tool for cybercriminals engaged in commodity malware-as-a-service operations. The attack employs a multi-stage delivery mechanism to distribute malware, phishing content, and scam landing pages.
Initial access occurs when users visit landing pages that mimic legitimate educational institutions. Upon arrival, obfuscated JavaScript code executes in their browsers, initiating the infection chain. The first-stage loader includes a hidden decoder that constructs a remote URL and injects malicious code into the page, while a one-time execution flag is stored in browser storage to prevent repeated detections.
Analysts from Macs-Hit discovered the malware infrastructure after recovering a JavaScript loader from the domain toxicsnake-wifes[.]com. This domain functions as a traffic distribution system (TDS) node that routes victims based on geographic location, device type, and browser information. The second stage attempts to fetch upstream payloads, though researchers encountered HTTP 504 errors, suggesting inactive or blocked upstream infrastructure at the time of analysis.
Security researchers have identified a complex traffic distribution network utilizing deceptive education-themed domains for malware and phishing attacks.
The investigation revealed a broader coordinated cluster of domains with similar operational security patterns. Related domains include pasangiklan[.]top, asangiklan[.]top, ourasolid[.]com, refanprediction[.]shop, and xelesex[.]top, all sharing education-themed branding and operating on similar infrastructure.
The operation utilizes bulletproof hosting providers, specifically HZ Hosting Ltd (ASN AS202015), which maintains a permissive abuse policy. The malicious domains are registered using disposable WHOIS information and depend on Regway nameservers, a common practice among CIS-region cybercriminals.
All domains resolve to IP addresses within the 185.33.84.0/23 netblock, with each domain assigned a dedicated IP address to evade broad IP-based blocking. The attackers employ automated certificate generation through Let’s Encrypt, obtaining free TLS certificates valid for ninety days, enabling rapid domain replacement and infrastructure rotation.
The obfuscated JavaScript loader uses tokenization to create unique session identifiers per visitor, preventing security sandboxes from accurately analyzing the threat by directing different analysis environments to benign content while delivering actual payloads to real victims.
Based on reporting by Cyber Security News.
