Security researchers described how defenders can use passive OSINT sources to identify and cluster malicious internet infrastructure, particularly HTTP(S)-based command-and-control servers, by analyzing artifacts left behind in headers, response bodies, passive DNS records, and TLS certificates. The reporting highlights that attacker operational mistakes, infrastructure automation, and efforts to mimic legitimate services often create repeatable fingerprints that can be searched at scale across internet-exposed hosts.
Censys demonstrated the approach with examples including Cobalt Strike servers that expose a characteristic HTTP 404 response pattern and infrastructure linked to APT29 malware such as WellMess and WellMail, which could be tracked through distinctive self-signed certificate distinguished names. The guidance recommends combining host telemetry with certificate and DNS data, preserving historical results, and documenting queries so security teams can build durable visibility into adversary infrastructure and uncover related systems over time.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Censys published a defensive threat-intelligence article describing passive OSINT methods for identifying and clustering malicious HTTP(S)-based infrastructure. It highlighted artifacts in HTTP headers, response bodies, and TLS certificates, using Cobalt Strike and APT29 WellMess infrastructure as examples.
A July 2020 NCSC UK advisory said APT29 targeted organizations connected to COVID-19 vaccine development. The advisory said the group used Citrix and VPN vulnerabilities and deployed the WellMess and WellMail malware families.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.