Following a single RedLine Stealer indicator, VMRay Labs surfaced a tailored business email compromise campaign against the maritime sector, and a cluster of attacker-owned domains that defenders can block today.
Threat Intelligence Report. 30 June 2026. Approximately a 9-minute read.
Key finding. Most threat intelligence work starts with a feed and ends with a blocklist. This investigation started with one RedLine Stealer indicator from VMRay’s UniqueSignal feed and ended somewhere its label never suggested: a tailored spear-phishing campaign against a maritime manufacturer, and behind it, a cluster of attacker-owned domains used to distribute the emails. The durable lesson is a practical one. The malware in any given phishing email rotates quickly and is largely disposable. The infrastructure that sends the emails lasts longer, which makes it the better thing to chase, and blocking it at the email gateway stops the next wave before it lands.
One indicator, one fingerprint
Every investigation needs a starting point. Here it was a single RedLine Stealer command-and-control address pulled from UniqueSignal, VMRay’s feed of fresh, behavior-verified indicators. Two things made it a good pivot candidate: it was recent, with communicating samples seen as late as April 2026, and it used a non-standard, specific port, which is far more selective to search on than a common one.
To turn that indicator into something reusable, the sample was detonated in the VMRay sandbox to capture the C2’s actual HTTP response. The response confirmed the family, RedLine’s SOAP-based communication was clearly present, but the more useful detail for hunting was a pairing: that specific high port alongside a particular Windows HTTP server banner. Neither is remarkable alone. Together, they were selective enough to become a fingerprint.
A second C2, then the real find
Searching internet-wide scan data for that fingerprint, without ever touching the target infrastructure, surfaced two more hosts. One was a genuine second RedLine C2. The other was a false positive, a useful reminder that a fingerprint is a filter, not a verdict, and every hit still has to be verified by hand.
That second confirmed C2 was where the investigation actually began. Its associated files, submitted since January and exclusively from South Korea, were not more infostealer samples. They were email files: business messages written as ongoing shipping correspondence, carrying ZIP attachments that delivered Formbook, a long-running form-grabber sold as a service.
This was not spray-and-pray malspam. The senders impersonated real companies in the maritime supply chain, the pretexts mimicked routine shipping conversations specific to that vertical, and the targeting was narrow, aimed at a South Korean manufacturer in the maritime sector. It was a tailored spear-phishing operation. While the sector and tradecraft overlap with previously reported maritime business email compromise activity, no shared infrastructure, tooling, or victimology was found, so the campaign is left unattributed.
Why business email compromise is worth the effort
Business email compromise, or BEC, is fraud built on social engineering rather than malware. The attacker impersonates someone the target trusts, a supplier, an executive, a legal contact, and uses that trust to slip into a routine transaction and redirect a payment. Often there is no malware at all. The leverage is a convincing email arriving at exactly the right moment in an expected conversation.
What makes BEC notable is the gap between how simple it is and how much it costs. In 2024, BEC accounted for a reported 2.77 billion dollars in losses across 21,442 incidents in the FBI’s IC3 data, second only to investment fraud by dollar value. Across 2022 to 2024, reported BEC losses approached 8.5 billion dollars. That disparity is the reason to chase the distribution infrastructure rather than the payload. The Formbook or RedLine sample in any single email is disposable. The domains and mail servers that send the emails have a longer shelf life, and cutting them off protects against the next round.
From one domain to a cluster
Five sender addresses came out of the campaign. The first task was separating the attacker’s own domains from legitimate accounts that had been spoofed or compromised. Three of the domains clearly belonged to real, long-established companies, dead ends for pivoting, since they lead back to a legitimate business. The ones that stood out were the newly registered look-alikes built to impersonate real firms.
Pivoting on one of those impersonation domains through its hosting provider and a specific server banner narrowed the field to a manageable set of hosts. Examining their TLS certificates for the same naming pattern already seen, short, company-impersonating names on low-cost top-level domains, exposed seven more fraudulent domains set up to distribute spear-phishing, each tied to an IP. The pattern held across all of them.
The takeaway
The investigation began with a commodity infostealer and ended with a durable, blockable cluster of attacker infrastructure. That is the shape of the payoff. Payloads rotate; distribution infrastructure outlives them. Going after the infrastructure, while a campaign is still live, is what turns a single indicator into protection against the emails that haven’t been sent yet.
Key takeaways
- A single, fresh indicator can be pivoted into a full infrastructure cluster that is far more useful than the indicator alone.
- A fingerprint built from selective, paired attributes (here, a specific port and server banner) is a filter for hunting, not a verdict. Every hit needs verification.
- The malware in a phishing email is disposable and rotates fast. The distribution infrastructure lasts longer, which makes it the more valuable target.
- Blocking attacker-owned sending domains and servers at the email gateway prevents the next wave of a campaign from ever arriving.
FAQ
What is RedLine Stealer? A commodity infostealer, first observed in 2020 and sold as a service, that harvests credentials, browser data, and cryptocurrency wallets. Its core infrastructure was disrupted by law enforcement in late 2024, but older builds and repackaged variants still surface in new incidents.
What is business email compromise (BEC)? A form of fraud in which an attacker impersonates a trusted party to insert themselves into a routine business transaction and redirect a payment. It relies on social engineering and often involves no malware at all.
What does “pivoting” mean in threat intelligence? Taking one indicator, such as an IP address, and examining everything connected to it, the files that contacted it, the certificates it served, its hosting and DNS history, to expand a single data point into a fuller picture of the attacker’s infrastructure.
Why chase the distribution infrastructure instead of the malware? Because the malware delivered in a given email is disposable and changes often, while the domains and servers used to send the emails persist. Blocking the infrastructure has a longer-lasting defensive effect.
Indicators of compromise
Block the following at your email gateway to prevent receipt of spear-phishing from this campaign. If any already appear in your environment, investigate the associated mail exchanges and rotate the credentials of any employees who interacted with them.
| Domain |
Associated IP |
acasiallc[.]shop |
185.252.24.78 |
ansysllc[.]shop |
185.252.24.52 |
softinsallc[.]online |
185.252.24.74 |
amdocsllc[.]shop |
176.114.8.101 |
taicom[.]top |
91.108.82.73 |
cimentosservices[.]online |
91.108.82.101 |
epsilongroup[.]online |
176.114.8.90 |
The full pivot chain, including the exact hunting queries used at each step, is available in the complete report. [Link to full report on vmray.com]
About VMRay
VMRay helps security teams detect and analyze novel, evasive, and targeted malware and phishing threats, with the accuracy and clarity they need to automate with confidence, respond faster, and build threat intelligence they can trust. Headquartered in Bochum, Germany, VMRay is trusted by enterprises, government organizations, and managed security providers worldwide.