CTG Server Limited is infrastructure associated with large-scale opportunistic exploitation activity, including a coordinated Christmas 2025 campaign targeting multiple Adobe ColdFusion vulnerabilities. Activity linked to this infrastructure involved thousands of requests against internet-exposed ColdFusion servers worldwide, primarily using JNDI/LDAP injection and out-of-band callback verification via Interactsh to confirm exploitation paths. The campaign was timed to coincide with a holiday period, indicating deliberate exploitation during reduced defender coverage. Observed targeting included systems in the United States, Spain, India, Canada, Chile, Germany, and Pakistan. Infrastructure associated with CTG Server Limited has also been linked to much broader malicious scanning and exploitation behavior, including millions of requests against hundreds of security defects across multiple technology stacks. The activity pattern is consistent with reconnaissance, scanning, and initial-access operations rather than a narrowly focused intrusion set. Available reporting assesses the operator behind this activity as likely functioning as an initial access broker seeking footholds for later exploitation or resale. CTG Server Limited appears in this context as the infrastructure provider associated with the activity rather than a formally established named intrusion group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.