Post

CaptiveCrunch Part 2: Burning More Threat Actor Infrastructure

Pivoting on Google's Findings to Identify More UNC7005/STORM-2945 Infrastructure

CaptiveCrunch Part 2: Burning More Threat Actor Infrastructure

The Campaign That Keeps On Giving

After the Google Threat Intelligence Group (GTIG) released their article covering the threat actor responsible for the CaptiveCrunch campaign that I had previously analyzed, I was very interested to do some infrastructure hunting based on it. They had identified some of the same infrastructure I had, but also provided many new indicators to hunt from and gave additional details of the campaign.

Their article describes three separate clusters, with the cluster attributed to UNC7005 being part of what was described in my earlier blog post and in Microsoft’s article, which I based mine on. The other clusters described in the GTIG article are attributed to UNC6293 and UNC5976, but my focus was only on the UNC7005 cluster.

The cluster attributed to UNC7005 is linked to device code phishing targeting both Microsoft and WhatsApp accounts, malware distribution and OAuth phishing. Their targets have been identified as academia, diplomatic, and NGO personnel in Ukraine, Western Europe, and the US. This activity appears to be separate from what was described by Microsoft in their CaptiveCrunch article, but it was linked to the same threat actor via infrastructure. This link was the IP address 104.194.159[.]150, which resolved to both a domain masquerading as a Microsoft domain (ms365-live[.]com) and a domain used for this device code phishing campaign (my-invite[.]org). This was also noted in my earlier blog post.

The UNC7005 Infrastructure Identified by GTIG

The new infrastructure identified as part of the UNC7005 cluster consists of various domains attempting to masquerade as WhatsApp, a Finnish Defence consultancy company, The American Chamber of Commerce in Ukraine and a security related conference. In addition, one C2 domain was identified as well as some previously uncovered infrastructure.

IndicatorDescription
chamber-ua[.]orgPhishing domain; attacker account email domain
wa-connect[.]euPhishing domain
wa-connect[.]netPhishing domain
wa-invite[.]comPhishing domain
wa-device[.]comPhishing domain
wa-meeting[.]comPhishing domain
shopinvite[.]orgPhishing domain
my-invite[.]orgPhishing domain; attacker account email domain
globsec[.]netPhishing domain; attacker account email domain
statistic-ms[.]liveENGINELIGHT C2
owa-ms365[.]comAttacker domain
m365-owa[.]comAttacker domain
ms365-live[.]comAttacker domain
31.57.243[.]154Related IP
38.146.28[.]75Related IP
104.194.159[.]150Related IP
finishoperations[.]comPhishing domain
finishoperations[.]orgPhishing domain
foc-share[.]comPhishing domain
share-foc[.]comPhishing domain
internal-share[.]comPhishing domain
foc-share[.]orgPhishing domain
keyereaonkendrick4@gmail[.]comEmail used to register statistic-ms[.]live

All Them Emails

One quirk identified earlier by ReliaQuest in their article can be seen across some of the infrastructure identified here. The threat actor often uses gmail addresses as domain registration information but fails to hide them via any domain privacy service. The threat actor also sometimes uses these same emails as SOA records for the domain. For example, ricardopayne226@gmail[.]com is part of the domain registration information and SOA records for share-foc[.]com and foc-share[.]com.

Shared Email Addresses These two domains share the same registration email.

Shared SOA record They also use the same email as SOA records.

Putting aside that this sounds like a pretty cool alias, it is not exactly a big surprise that these very similar domains are registered using the same email address. It does still provide an additional data point and a way to provide additional confirmation that domains identified later on are indeed related to this cluster and/or the threat actor. All identified email addresses can be found in the Identified UNC7005 Infrastructure chapter.


Who is Mister Shell

Moving on to the infrastructure analysis. The domain statistic-ms[.]live was identified as a C2 by GTIG and historically it has resolved to two IP addresses:

144.172.114[.]192

104.194.151[.]133

Of these, the latter IP address resulted in more interesting pivots. Two additional domains of note have resolved to this IP address, wa-connect[.]eu, which was already noted as part of the threat actor’s infrastructure and mslivetest.duckdns[.]org. Considering the statistic-ms[.]live domain was eventually used as a C2, the mslivetest.duckdns[.]org domain could have been used for some sort of testing before the main infrastructure was set up.

Domain resolutions The resolution history for one of the C2 IP addresses revealed additional pivot points.

Checking this domain from urlscan reveals a landing page that is trying to appear as a legitimate monitoring solution. This content is also identical to what was served from statistic-ms[.]live.

Page content Additional pivot points revealed from urlscan.

The resources served by the page allowed for further pivoting. The auth.php file served from the site is also found on two other hosts from urlscan:

2.26.53[.]194

45.61.130[.]32

These hosts have dubious scores on Virustotal and various malicious files have been communicating to these addresses, almost certainly making them C2s. Both IP addresses have also been seen by urlscan to host what appears to be a C2 panel:

Mister Shell The pivoting reveals the likely type of C2 panel used by the threat actor.

This same C2 panel can be seen on eight additional hosts based on its rather unique title and one javascript resource used in the page. As most of the IP addresses hosting this Mister Shell panel have not been connected to any relevant domains and are hosted in ASNs not seen in this campaign, it is likely most of them are not relevant to this campaign specifically. It does, however, seem likely that UNC7005 was using this specific C2 panel or at least parts of it in the background.

Mister Shell Pivots The C2 panel can also be identified in use elsewhere.


Domains For Everyone

The article by GTIG identified over a dozen different domains which provided many opportunities for pivot points. Most of the domains were set up for a phishing site and resolved to a single IP address which only hosted one domain. But some IP addresses hosted multiple threat actor domains. Most of them were already identified by GTIG, for example both shopinvite[.]org and wa-invite[.]com had resolved to the same IP address 82.40.23[.]74.

But some of the IP addresses did reveal additional threat actor connected domains:

The IP address 144.172.114[.]192 hosting the C2 domain statistic-ms[.]live was also used for the domain docs-viewer[.]org, which was serving a site appearing to offer a PDF viewer. Notably, the visual style of this page (on the right) is very similar to a landing page identified by GTIG (on the left).

Docs-viewer page Notable similarities with the “PDF Viewer” site and phishing site identified by GTIG.


The IP address 79.133.57[.]111 that was used to host WhatsApp phishing domains wa-device[.]com and wa-meeting[.]com identified by GTIG, also hosted wa-device[.]net, similarly used for a WhatsApp phishing site. The domain wa-device[.]net was registered using the email address arcingcoccidiosis@gmx[.]com, which was also used to register wa-device[.]org. I was unable to confirm this latter domain was used for the same activity as it appears not to have resolved to any IP address. It is possible this domain was meant to go live later or was simply forgotten.

WhatsApp Phishing Site The website on wa-device[.]net can be seen hosting phishing content similar to the other WhatsApp themed sites.


The domain chamber-ua[.]org, masquerading as The American Chamber of Commerce in Ukraine and identified by GTIG, was one of the domains that did not appear to have any similar variants. However, digging a bit deeper, some additional infrastructure could be dug up. The domain was used to host a site that was claiming to be a private site for The American Chamber of Commerce in Ukraine and asking for credentials.

Chamber of Commerce Site The site was claiming to be a “Private Workspace” for the organization it was masquerading as.

None of the resources used by the site were unique and the title “Private Workspace” was very common. However, when combining the title with the ASN that the threat actor has commonly used during this campaign, some new findings can be made.

New findings from urlscan Pivoting via urlscan reveals three additional domains.

New findings from FOFA Pivoting via FOFA reveals one new domain.

FOFA reveals the new domain ukrinform-share[.]net and the IP address 104.194.157[.]175 that it resolved to. This was used to host an essentially identical site claiming to be a private site, likely for the National News Agency of Ukraine (ukrinform.net).

Urlscan reveals three additional domains and IP addresses hosting similar sites, the only difference being just a different icon for the organization they are masquerading as:

The domain chathamhouse[.]eu, masquerading as the international affairs think tank Chatham House (chathamhouse.org), and the IP address 107.189.24[.]79 serving this site.

The domain antac[.]org, masquerading as a Ukrainian NGO (Anti-Corruption Action Center, antac.org.ua), and the IP address 104.194.158[.]50 serving this site.

The domain trident-solutions[.]org, likely masquerading as a United States defense logistics and brokering firm (trident-solutions[.]us), and the IP address 107.189.22[.]209 serving this site.

As further confirmation that these domains are related to the threat actor, the SOA records for ukrinform-share[.]net and chathamhouse[.]eu reveal more gmail addresses. For ukrinform-share[.]net the address amipiqokuw980@gmail[.]com can be found and for chathamhouse[.]eu the kapukec366@gmail[.]com address.


Conclusion

Google Threat Intelligence Group’s article describes a phishing and malware distribution campaign connected to UNC7005/STORM-2945 that is separate, but related to the campaign dubbed CaptiveCrunch by Microsoft. In the CaptiveCrunch campaign victims were targeted via compromised captive portals and/or router infrastructure. These campaigns were linked to the same threat actor by pivoting on their infrastructure.

The campaign documented by GTIG revealed 15 domains connected to the threat actor that were not published in the article by Microsoft or were not identified in my previous post. I managed to identify eight additional domains related to this campaign and threat actor. For some reason GTIG did not publish any new IP addresses as indicators. This is odd considering the domains they listed were mostly hosted on IP addresses that were not previously identified and most seemed to be only used for this campaign. I will list these IP addresses alongside the ones identified through pivoting, which all together come to 20 IP addresses related to this campaign. Finally I managed to identify seven email addresses related to this threat actor and four new target/victim organizations. A complete list of the indicators can be seen just below.

Maltego Graph Graph describing the starting points and pivots.

Identified UNC7005 Infrastructure:

Initial indicators:

IndicatorDescription
chamber-ua[.]orgPhishing domain; attacker account email domain
wa-connect[.]euPhishing domain
wa-connect[.]netPhishing domain
wa-invite[.]comPhishing domain
wa-device[.]comPhishing domain
wa-meeting[.]comPhishing domain
shopinvite[.]orgPhishing domain
my-invite[.]orgPhishing domain; attacker account email domain
globsec[.]netPhishing domain; attacker account email domain
statistic-ms[.]liveENGINELIGHT C2
owa-ms365[.]comAttacker domain
m365-owa[.]comAttacker domain
ms365-live[.]comAttacker domain
31.57.243[.]154Related IP
38.146.28[.]75Related IP
104.194.159[.]150Related IP
finishoperations[.]comPhishing domain
finishoperations[.]orgPhishing domain
foc-share[.]comPhishing domain
share-foc[.]comPhishing domain
internal-share[.]comPhishing domain
foc-share[.]orgPhishing domain
keyereaonkendrick4@gmail[.]comEmail used to register statistic-ms[.]live

Additional indicators:

IndicatorDescriptionConfidenceFirst seen
144.172.114[.]192C2 address, statistic-ms[.]live resolved hereHigh2026-03-16
docs-viewer[.]orgLikely phishing, resolved to 144.172.114[.]192High2026-04-22
104.194.151[.]133statistic-ms[.]live & wa-connect[.]eu resolvedHigh2026-05-20
mslivetest.duckdns[.]orgLikely C2, resolved to 104.194.151[.]133High2026-04-22
2.26.53[.]194Shares C2 indicator with 104.194.151[.]133Low2026-07-30
45.61.130[.]32Shares C2 indicator with 104.194.151[.]133Low2026-05-20
104.194.149[.]228globsec[.]net resolved hereHigh2026-05-13
45.59.122[.]181chamber-ua[.]org resolved hereHigh2026-02-17
ukrinform-share[.]netLikely phishing, identical to chamber-ua[.]orgHigh2026-01-28
104.194.157[.]175ukrinform-share[.]net resolved hereHigh2026-01-28
amipiqokuw980@gmail[.]comSOA Record for ukrinform-share[.]netHigh2026-01-28
chathamhouse[.]euLikely phishing, identical to chamber-ua[.]orgHigh2026-02-24
107.189.24[.]79chathamhouse[.]eu resolved hereHigh2026-02-24
kapukec366@gmail[.]comSOA Record for chathamhouse[.]euHigh2026-02-24
trident-solutions[.]orgLikely phishing, identical to chamber-ua[.]orgHigh2026-03-18
107.189.22[.]209trident-solutions[.]org resolved hereHigh2026-03-18
antac[.]orgLikely phishing, identical to chamber-ua[.]orgHigh2026-02-16
104.194.158[.]50antac[.]org resolved hereHigh2026-02-16
104.194.143[.]34wa-connect[.]eu & wa-connect[.]net resolvedHigh2026-02-26
mikeplug7537@gmail[.]comSOA Record for wa-connect[.]euHigh2026-03-06
45.59.114[.]125wa-connect[.]net resolved hereHigh2026-05-18
79.133.57[.]111wa-meeting[.]com & wa-device[.]com resolvedHigh2026-07-28
wa-device[.]netPhishing, resolved to 79.133.57[.]111High2026-08-06
arcingcoccidiosis@gmx[.]comDomain info & SOA for wa-device[.]netHigh2026-07-30
wa-device[.]orgarcingcoccidiosis@gmx[.]com as domain infoHigh2026-07-30
82.40.23[.]74wa-invite[.]com & shopinvite[.]org resolvedHigh2026-05-27
216.126.237[.]109finishoperations[.]com resolved hereHigh2026-07-31
yucofifuj680@gmail[.]comSOA & domain info for finishoperations[.]comHigh2026-07-31
yucofifuj680@gmail[.]comSOA & domain info for finishoperations[.]orgHigh2026-08-06
144.172.105[.]230finishoperations[.]org resolved hereHigh2026-08-06
45.59.124[.]49foc-share[.]com resolved hereHigh2026-08-07
ricardopayne226@gmail[.]comDomain info & SOA for foc-share[.]comHigh2026-08-07
ricardopayne226@gmail[.]comDomain info & SOA for share-foc[.]comHigh2026-08-11
144.172.65[.]14foc-share[.]org resolved hereHigh2026-08-13
djfkfjfofkbf@gmail[.]comDomain info & SOA for foc-share[.]orgHigh2026-08-12
djfkfjfofkbf@gmail[.]comDomain info & SOA for internal-share[.]comHigh2026-08-11
45.61.148[.]214internal-share[.]com resolved hereHigh2026-08-11
144.172.115[.]17share-foc[.]com resolved hereHigh2026-08-10
This post is licensed under CC BY 4.0 by the author.