TOXICSNAKE is a traffic distribution network (TDS) and malware delivery operation identified by researchers as using deceptive education-themed domains and university-style branding to deliver malware, phishing, and scam content. Victims are lured to landing pages impersonating educational institutions, where obfuscated JavaScript executes in the browser to initiate the infection chain. The first-stage loader contains a hidden decoder that constructs a remote URL, injects malicious code into the page, and stores a one-time execution flag in browser storage to reduce repeat execution and detection. A recovered JavaScript loader from toxicsnake-wifes[.]com showed that the infrastructure routes victims to different payloads based on geolocation, device type, and browser fingerprinting. The second stage attempts to retrieve upstream payloads, although researchers observed HTTP 504 errors during analysis. The operation is assessed as part of a coordinated domain cluster sharing the same operational security patterns and education-themed lures, including pasangiklan[.]top, asangiklan[.]top, ourasolid[.]com, refanprediction[.]shop, and xelesex[.]top. The infrastructure uses bulletproof hosting at HZ Hosting Ltd (ASN AS202015), disposable WHOIS data, Regway nameservers, dedicated IPs in the 185.33.84.0/23 netblock, and Let’s Encrypt certificates with 90-day validity. The JavaScript loader also uses tokenization-based session identifiers and routing logic to hinder sandbox analysis by serving benign content to analysis environments while delivering malicious payloads to real victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A traffic distribution system (TDS) / malicious infrastructure cluster using education-themed spoofed domains and an obfuscated JavaScript multi-stage loader to fingerprint visitors (geo/device/browser), evade sandboxing via tokenized session identifiers, and route victims to different downstream payloads (malware, phishing, scam pages).
Multi-domain traffic distribution system used to route/shape malicious traffic; specific payloads are not described in the provided content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.