VYPR
researchPublished Sep 15, 2026· 1 source

Malware Campaigns Leverage Rotating Infrastructure to Evade Detection

Modern malware operations increasingly rely on rapidly changing domains and hosting infrastructure, creating significant detection gaps for security operations centers.

Security operations centers (SOCs) are facing an escalating challenge in detecting modern malware campaigns due to the attackers' sophisticated use of rotating infrastructure. The traditional approach of blocking static indicators of compromise (IOCs) is becoming increasingly futile as threat actors rapidly change their hosting domains, IP addresses, and phishing flows. This dynamic infrastructure allows malware to persist and spread, creating a critical detection gap that leaves organizations more vulnerable.

A recent analysis of a large-scale RMM phishing campaign, initially appearing to target Canada with fake tax documents, revealed its true scope: 46 countries were affected, with 45% of activity in the United States. Researchers identified 425 kit URLs across 240 hosts, and strikingly, 94% of these hosts were active for only a single day. This rapid infrastructure turnover, while the underlying attack model remained consistent, highlights the difficulty SOCs face in keeping pace with evolving threats.

Another example, the 3DBlast phishing kit, targets users impersonating Microsoft 365 and Google services. This kit not only rotates its infrastructure but also employs a variety of sophisticated phishing techniques, including Browser-in-the-Browser (BitB), OAuth/device-code phishing, adversary-in-the-middle (AiTM), and DOM relay. The adaptability and multi-pronged approach of such kits underscore the need for detection methods that go beyond single-indicator blocking.

The core issue is that the lifespan of individual IOCs is often far shorter than the lifespan of the threat campaign itself. When detection relies on outdated threat intelligence, every infrastructure change by attackers can create a new window of opportunity for them to operate undetected. This necessitates a shift towards more dynamic and timely threat intelligence feeds.

To combat this challenge, SOC analysts require immediate access to fresh threat data, broad visibility into emerging infrastructure, and sufficient context to investigate any threats that bypass initial defenses. Threat intelligence platforms that continuously deliver new malicious indicators from real-world sandbox investigations directly into SIEM, SOAR, and firewall systems are crucial.

Solutions like ANY.RUN's Threat Intelligence Feeds aggregate data from thousands of sandbox investigations, providing a high volume of unique IOCs with a low false-positive rate. This ensures that security controls are continuously updated with relevant, actionable intelligence, significantly reducing the time malicious infrastructure goes undetected.

While fresh intelligence helps close detection gaps, effective incident response still requires analysts to understand the nature of the threat. Tools that allow analysts to pivot from an IOC to related infrastructure, activity, and historical threat data, coupled with access to behavioral evidence from sandbox sessions, are vital for validating threats and making swift decisions.

In conclusion, the rise of rotating infrastructure in malware campaigns does not necessarily mean attackers are constantly inventing new attack models. Instead, they are adept at rapidly changing the delivery mechanisms to evade detection. The key for SOC leaders is to ensure their detection capabilities can keep pace with these changes, leveraging timely threat intelligence to shorten the window between new malicious infrastructure appearing and its effective detection.

Synthesized by Vypr AI