DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns
DNS Pivoting Reveals Shared Infrastructure Across LokiBot (TL-2026-1485), also tracked as Beagle, is a medium-severity malware campaign, first published 2026-07-18. It has no confirmed attribution, affects Cross-platform Windows endpoints (LokiBot, Xworm, Remcos targets), maps to 48 MITRE ATT&CK techniques (T1003, T1016, T1027), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1485
- Threat ID
- TL-2026-1485
- Also known as
- Beagle, Mitglieder, Lodeight
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-18
- Last reviewed
- 2026-07-18
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- all-sectors, finance, consumer, retail, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in DNS Pivoting Reveals Shared Infrastructure Across LokiBot
Malware and tooling: Bagle, LokiBot, Remcos, XWorm, ThreatFox, Validin, VirusTotal
Embee Research used passive DNS pivoting via Validin to trace and cluster active C2 infrastructure for LokiBot (sempersim[.]su), a Bagle-worm-linked lookalike-domain cluster impersonating iCloud, and Xworm/Remcos infrastructure discovered through duckdns dynamic-DNS domains and CIDR-range expansion (194.147.140.0/24, ~464 duckdns domains). The analysis surfaces possible infrastructure sharing between LokiBot and Bagle operators and documents threat actors' heavy reliance on dynamic DNS and rapid infrastructure rotation for C2 resilience.
How DNS Pivoting Reveals Shared Infrastructure Across LokiBot works
In a March 2024 research report, Embee Research demonstrated three case studies of passive-DNS-driven infrastructure hunting using the Validin platform, corroborated with VirusTotal and ThreatFox. The first case study pivots on the LokiBot C2 domain sempersim[.]su and associated IP history to identify additional LokiBot infrastructure and confirm activity via VirusTotal detections. The second case study examines a cluster of lookalike domains impersonating iCloud (lcloud.com[.]de, lcloud.com[.]se, www.icloud-find-online[.]me) that resolve to shared IP space also linked to Bagle-worm-associated infrastructure, suggesting the same bulletproof-hosting or infrastructure-broker relationships are reused across malware families that are otherwise unrelated in lineage (a banking/credential-stealer trojan vs. a legacy mass-mailing worm/Trojan-proxy family). The third case study pivots on dynamic DNS: two duckdns.org subdomains (marxrwo9090.duckdns[.]org and febxworm39090.duckdns[.]org) tied to Xworm activity, and elastolut.duckdns[.]org tied to Remcos RAT C2 (11 VirusTotal detections), which the analysts expand via reverse-IP and CIDR-range queries against 194.147.140.0/24 to enumerate roughly 464 additional duckdns-hosted domains registered by the same or affiliated operators. IP pivots (104.237.252.28, 194.295.220.41, 194.147.140.138) show short-lived resolution windows consistent with rapid infrastructure rotation, and the report notes adoption of Cloudflare-fronting as of 2024-03-19 to mask origin infrastructure. Collectively the report is a methodology showcase for hunting malware C2 via passive DNS/certificate pivoting (Validin), reverse-IP clustering, dynamic-DNS abuse detection, and CIDR-range expansion, applied against three live and currently-tracked malware families: LokiBot (credential/banking stealer, MITRE S0447), Xworm (modular .NET RAT with ransomware and DDoS plugins), and Remcos (commercial-turned-criminal RAT with keylogging/webcam/audio surveillance and COM-based UAC bypass persistence). The Bagle worm reference is historical/lineage context: Bagle (aka Beagle/Mitglieder, first observed January 2004) was a mass-mailing worm that dropped Trojan-proxy components and built spam-relay botnets; its continued relevance here is limited to infrastructure/hosting overlap with the iCloud-lookalike cluster rather than active 2024 Bagle-worm code execution.
MITRE ATT&CK techniques used in TL-2026-1485
Credential Access
T1003 OS Credential Dumping; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
Discovery
T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1027.002 Software Packing; T1036 Masquerading; T1055.012 Process Hollowing; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1218.011 Rundll32; T1497.003 Time Based Checks; T1564.001 Hidden Files and Directories; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1106 Native API; T1204.002 Malicious File
Persistence
T1053.005 Scheduled Task; T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder
Privilege Escalation
T1055.001 Dynamic-link Library Injection; T1548.002 Bypass User Account Control
Collection
T1056.001 Keylogging; T1113 Screen Capture; T1119 Automated Collection; T1123 Audio Capture; T1125 Video Capture
Command and Control
T1071.001 Web Protocols; T1090.002 External Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568.002 Domain Generation Algorithms; T1573.001 Symmetric Cryptography
defense-impairment
Impact
T1486 Data Encrypted for Impact; T1498 Network Denial of Service
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
T1583.001 Domains; T1583.004 Server; T1585.001 Social Media Accounts
Reconnaissance
Affected products and versions in DNS Pivoting Reveals Shared Infrastructure Across LokiBot
- Cross-platform — Windows endpoints (LokiBot, Xworm, Remcos targets)
Vulnerable versions: All supported Windows versions
Remediation for DNS Pivoting Reveals Shared Infrastructure Across LokiBot
Immediate actions
- Block sempersim[.]su and all associated LokiBot C2 domains/IPs at DNS and perimeter firewall
- Block lcloud.com[.]de, lcloud.com[.]se, www.icloud-find-online[.]me at DNS resolver and web proxy as known iCloud-phishing lookalikes
- Block marxrwo9090.duckdns[.]org, febxworm39090.duckdns[.]org, elastolut.duckdns[.]org at DNS and firewall
- Block/alert on IPs 104.237.252.28, 194.295.220.41, 194.147.140.138 and the 194.147.140.0/24 CIDR range
- Sinkhole or heavily scrutinize outbound DNS queries to duckdns.org and other dynamic-DNS providers from endpoints without a documented business need
Workarounds
- Restrict or monitor outbound connections to known dynamic-DNS provider domains (duckdns.org, no-ip, dyndns) at the network egress layer
- User-awareness training on iCloud-lookalike phishing domains (L/I character confusion, lookalike TLD patterns)
Longer-term hardening
- Deploy detection content for LokiBot, Xworm, and Remcos process/behavioral indicators (credential-store access, keylogging APIs, scheduled-task persistence, COM-based UAC bypass)
- Build a recurring passive-DNS/CIDR pivoting hunt workflow (Validin, VirusTotal, ThreatFox) to proactively enumerate dynamic-DNS-hosted C2 clusters before campaign delivery
- Establish DNS threat-intel feeds that flag newly-registered dynamic-DNS subdomains resolving to previously-flagged CIDR ranges
- Monitor for infrastructure reuse patterns across seemingly unrelated malware families as a pivot for attribution/cluster tracking
Timeline of DNS Pivoting Reveals Shared Infrastructure Across LokiBot
- Bagle (Beagle/Mitglieder) mass-mailing worm first detected, dropping Trojan-proxy components used to build spam-relay botnets.
- LokiBot first offered for sale on cybercrime forums by the actor alias 'lokistov' for approximately $540 USD.
- CISA publishes advisory AA20-266A documenting continued widespread LokiBot activity against U.S. organizations.
- Embee Research observes adoption of Cloudflare CDN fronting on tracked infrastructure, complicating direct-IP attribution.
- CIDR-range expansion of 194.147.140.0/24 surfaces approximately 464 additional duckdns-hosted domains linked to the same hosting cluster.
- Remcos RAT C2 elastolut.duckdns[.]org identified with 11 corroborating VirusTotal detections.
- Xworm C2 domains marxrwo9090.duckdns[.]org and febxworm39090.duckdns[.]org identified via dynamic-DNS analysis.
- Lookalike iCloud-phishing domains (lcloud.com[.]de, lcloud.com[.]se, www.icloud-find-online[.]me) identified sharing hosting infrastructure with Bagle-linked operators, suggesting cross-family infrastructure sharing.
- LokiBot C2 sempersim[.]su pivoted via IP-history analysis to surface additional related LokiBot infrastructure, corroborated with VirusTotal detections.
- Embee Research publishes 'Infrastructure Analysis With DNS Pivoting,' documenting LokiBot, Bagle-linked, Xworm, and Remcos infrastructure clustering via Validin passive DNS pivoting.
Sources cited for DNS Pivoting Reveals Shared Infrastructure Across LokiBot
- Infrastructure Analysis With DNS Pivoting
- LokiBot Malware | CISA Advisory AA20-266A
- Lokibot, Software S0447 | MITRE ATT&CK
- LokiBot Malware White Paper
- XWorm v7 RAT: Technical Analysis of Infection Chain, C2 Protocol, and Plugin Architecture
- XWorm Malware: Analysis, Detection, Removal
- The Rise of XWorm RAT: What Cybersecurity Teams Need to Know Now
- Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Four
- Remcos RAT Analysis: How the Windows Remote Access Trojan Operates
- ZPHP Campaign Delivering Remcos RAT Impacting SLTTs
- Bagle (computer worm)
- The Bagle botnet
- Email-Worm:W32/Bagle
Threats related to DNS Pivoting Reveals Shared Infrastructure Across LokiBot
- Operation Turb00: Multi-Stage HijackLoader (IDAT Loader) Campaign Delivers Vidar v2.1 Infostealer and SnappyClient RAT via PNG-IDAT Steganography
- Remcos RAT: Technical Analysis of Windows Remote Access Trojan Operations
- Multi-Stage Steganographic Loader Campaign Deploying Remcos RAT and Diverse Stealer Payloads (K7 Labs, June 2026)
- Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power Infrastructure Targets
- Multi-Stage Steganographic Loader Delivers Remcos RAT and Rotating Infostealers via .NET Bitmap Resource Steganography and AppDomain.Load In-Memory Execution
- SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)
Detection coverage for TL-2026-1485
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1485 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.