A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.
Reported 02 Jul 2026 by otx · Severity: medium
An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fin