{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/infrastructure-tracking/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["rumour"],"_cs_tags":["malware-delivery","command-and-control","threat-intelligence","infrastructure-tracking"],"_cs_type":"rumour","_cs_vendors":[],"content_html":"\u003cp\u003eThis intelligence brief, authored by Joe Nazario (dti.domaintools.com), provides the fifth installment in a series monitoring infrastructure utilized by Chinese-based threat actors for malware distribution and command-and-control (C2) operations. The report focuses on characterizing domain-based indicators that support payload staging and the maintenance of persistent backdoors within victim networks. For defenders, this research is critical for identifying and blocking adversary infrastructure at the network perimeter, thereby disrupting the communication loop between infected endpoints and actor-controlled servers. By integrating these indicators into DNS sinkholes and threat intelligence feeds, organizations can proactively limit the success of these ongoing campaigns.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe identified infrastructure is actively used to facilitate malicious activity, including payload delivery and long-term command-and-control. Continued exposure to these domains poses a significant risk for unauthorized access, data exfiltration, and the establishment of persistent footholds within targeted enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview DNS and proxy logs for any communication with infrastructure identified in the source research.\u003c/li\u003e\n\u003cli\u003eIntegrate domain intelligence from the DomainTools research report into existing enterprise blocklists.\u003c/li\u003e\n\u003cli\u003eMonitor for outbound traffic patterns consistent with C2 beaconing using tools like Zeek or Suricata.\u003c/li\u003e\n\u003cli\u003eUse the findings from the research to perform historical lookbacks in SIEM telemetry to identify past interaction with these command-and-control domains.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-21T22:15:39Z","date_published":"2026-08-21T22:15:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-chinese-malware-domains/","summary":"This report catalogs domain infrastructure identified in ongoing malware delivery and command-and-control operations linked to Chinese-based threat actors, facilitating improved network-level detection and defensive blocking.","title":"Infrastructure Tracking of Chinese Malware Delivery Operations","url":"https://feed.craftedsignal.io/briefs/2026-08-chinese-malware-domains/"}],"language":"en","title":"CraftedSignal Threat Feed - Infrastructure-Tracking","version":"https://jsonfeed.org/version/1.1"}