DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns

DNS Pivoting Reveals Shared Infrastructure Across LokiBot (TL-2026-1485), also tracked as Beagle, is a medium-severity malware campaign, first published 2026-07-18. It has no confirmed attribution, affects Cross-platform Windows endpoints (LokiBot, Xworm, Remcos targets), maps to 48 MITRE ATT&CK techniques (T1003, T1016, T1027), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-1485

Threat ID
TL-2026-1485
Also known as
Beagle, Mitglieder, Lodeight
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-07-18
Last reviewed
2026-07-18
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
all-sectors, finance, consumer, retail, technology
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in DNS Pivoting Reveals Shared Infrastructure Across LokiBot

Malware and tooling: Bagle, LokiBot, Remcos, XWorm, ThreatFox, Validin, VirusTotal

Embee Research used passive DNS pivoting via Validin to trace and cluster active C2 infrastructure for LokiBot (sempersim[.]su), a Bagle-worm-linked lookalike-domain cluster impersonating iCloud, and Xworm/Remcos infrastructure discovered through duckdns dynamic-DNS domains and CIDR-range expansion (194.147.140.0/24, ~464 duckdns domains). The analysis surfaces possible infrastructure sharing between LokiBot and Bagle operators and documents threat actors' heavy reliance on dynamic DNS and rapid infrastructure rotation for C2 resilience.

How DNS Pivoting Reveals Shared Infrastructure Across LokiBot works

In a March 2024 research report, Embee Research demonstrated three case studies of passive-DNS-driven infrastructure hunting using the Validin platform, corroborated with VirusTotal and ThreatFox. The first case study pivots on the LokiBot C2 domain sempersim[.]su and associated IP history to identify additional LokiBot infrastructure and confirm activity via VirusTotal detections. The second case study examines a cluster of lookalike domains impersonating iCloud (lcloud.com[.]de, lcloud.com[.]se, www.icloud-find-online[.]me) that resolve to shared IP space also linked to Bagle-worm-associated infrastructure, suggesting the same bulletproof-hosting or infrastructure-broker relationships are reused across malware families that are otherwise unrelated in lineage (a banking/credential-stealer trojan vs. a legacy mass-mailing worm/Trojan-proxy family). The third case study pivots on dynamic DNS: two duckdns.org subdomains (marxrwo9090.duckdns[.]org and febxworm39090.duckdns[.]org) tied to Xworm activity, and elastolut.duckdns[.]org tied to Remcos RAT C2 (11 VirusTotal detections), which the analysts expand via reverse-IP and CIDR-range queries against 194.147.140.0/24 to enumerate roughly 464 additional duckdns-hosted domains registered by the same or affiliated operators. IP pivots (104.237.252.28, 194.295.220.41, 194.147.140.138) show short-lived resolution windows consistent with rapid infrastructure rotation, and the report notes adoption of Cloudflare-fronting as of 2024-03-19 to mask origin infrastructure. Collectively the report is a methodology showcase for hunting malware C2 via passive DNS/certificate pivoting (Validin), reverse-IP clustering, dynamic-DNS abuse detection, and CIDR-range expansion, applied against three live and currently-tracked malware families: LokiBot (credential/banking stealer, MITRE S0447), Xworm (modular .NET RAT with ransomware and DDoS plugins), and Remcos (commercial-turned-criminal RAT with keylogging/webcam/audio surveillance and COM-based UAC bypass persistence). The Bagle worm reference is historical/lineage context: Bagle (aka Beagle/Mitglieder, first observed January 2004) was a mass-mailing worm that dropped Trojan-proxy components and built spam-relay botnets; its continued relevance here is limited to infrastructure/hosting overlap with the iCloud-lookalike cluster rather than active 2024 Bagle-worm code execution.

MITRE ATT&CK techniques used in TL-2026-1485

Credential Access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.002 Software Packing; T1036 Masquerading; T1055.012 Process Hollowing; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1218.011 Rundll32; T1497.003 Time Based Checks; T1564.001 Hidden Files and Directories; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1106 Native API; T1204.002 Malicious File

Persistence

T1053.005 Scheduled Task; T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder

Privilege Escalation

T1055.001 Dynamic-link Library Injection; T1548.002 Bypass User Account Control

Collection

T1056.001 Keylogging; T1113 Screen Capture; T1119 Automated Collection; T1123 Audio Capture; T1125 Video Capture

Command and Control

T1071.001 Web Protocols; T1090.002 External Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568.002 Domain Generation Algorithms; T1573.001 Symmetric Cryptography

defense-impairment

T1112 Modify Registry

Impact

T1486 Data Encrypted for Impact; T1498 Network Denial of Service

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.004 Server; T1585.001 Social Media Accounts

Reconnaissance

T1589.002 Email Addresses

Affected products and versions in DNS Pivoting Reveals Shared Infrastructure Across LokiBot

  • Cross-platform — Windows endpoints (LokiBot, Xworm, Remcos targets)
    Vulnerable versions: All supported Windows versions

Remediation for DNS Pivoting Reveals Shared Infrastructure Across LokiBot

Immediate actions

  • Block sempersim[.]su and all associated LokiBot C2 domains/IPs at DNS and perimeter firewall
  • Block lcloud.com[.]de, lcloud.com[.]se, www.icloud-find-online[.]me at DNS resolver and web proxy as known iCloud-phishing lookalikes
  • Block marxrwo9090.duckdns[.]org, febxworm39090.duckdns[.]org, elastolut.duckdns[.]org at DNS and firewall
  • Block/alert on IPs 104.237.252.28, 194.295.220.41, 194.147.140.138 and the 194.147.140.0/24 CIDR range
  • Sinkhole or heavily scrutinize outbound DNS queries to duckdns.org and other dynamic-DNS providers from endpoints without a documented business need

Workarounds

  • Restrict or monitor outbound connections to known dynamic-DNS provider domains (duckdns.org, no-ip, dyndns) at the network egress layer
  • User-awareness training on iCloud-lookalike phishing domains (L/I character confusion, lookalike TLD patterns)

Longer-term hardening

  • Deploy detection content for LokiBot, Xworm, and Remcos process/behavioral indicators (credential-store access, keylogging APIs, scheduled-task persistence, COM-based UAC bypass)
  • Build a recurring passive-DNS/CIDR pivoting hunt workflow (Validin, VirusTotal, ThreatFox) to proactively enumerate dynamic-DNS-hosted C2 clusters before campaign delivery
  • Establish DNS threat-intel feeds that flag newly-registered dynamic-DNS subdomains resolving to previously-flagged CIDR ranges
  • Monitor for infrastructure reuse patterns across seemingly unrelated malware families as a pivot for attribution/cluster tracking

Timeline of DNS Pivoting Reveals Shared Infrastructure Across LokiBot

  • Bagle (Beagle/Mitglieder) mass-mailing worm first detected, dropping Trojan-proxy components used to build spam-relay botnets.
  • LokiBot first offered for sale on cybercrime forums by the actor alias 'lokistov' for approximately $540 USD.
  • CISA publishes advisory AA20-266A documenting continued widespread LokiBot activity against U.S. organizations.
  • Embee Research observes adoption of Cloudflare CDN fronting on tracked infrastructure, complicating direct-IP attribution.
  • CIDR-range expansion of 194.147.140.0/24 surfaces approximately 464 additional duckdns-hosted domains linked to the same hosting cluster.
  • Remcos RAT C2 elastolut.duckdns[.]org identified with 11 corroborating VirusTotal detections.
  • Xworm C2 domains marxrwo9090.duckdns[.]org and febxworm39090.duckdns[.]org identified via dynamic-DNS analysis.
  • Lookalike iCloud-phishing domains (lcloud.com[.]de, lcloud.com[.]se, www.icloud-find-online[.]me) identified sharing hosting infrastructure with Bagle-linked operators, suggesting cross-family infrastructure sharing.
  • LokiBot C2 sempersim[.]su pivoted via IP-history analysis to surface additional related LokiBot infrastructure, corroborated with VirusTotal detections.
  • Embee Research publishes 'Infrastructure Analysis With DNS Pivoting,' documenting LokiBot, Bagle-linked, Xworm, and Remcos infrastructure clustering via Validin passive DNS pivoting.

Sources cited for DNS Pivoting Reveals Shared Infrastructure Across LokiBot

Threats related to DNS Pivoting Reveals Shared Infrastructure Across LokiBot

Detection coverage for TL-2026-1485

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1485 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats