Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk6 min

How an OPSEC Failure Exposed Coquettte’s Malware Campaign on Bulletproof Hosting

DomainTools traced Coquettte’s fake antivirus campaign through an exposed directory, Proton66-associated hosting and the Rugmi/Penguish loader. Here is what is confirmed, what remains inference, and how to respond.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An exposed directory helped DomainTools connect a fake antivirus website, Proton66-associated infrastructure and a malware-delivery operation attributed to the emerging actor Coquettte. The April 4, 2025 report describes a chain that used the Cyber Secure Pro lure to deliver a Windows installer and, according to DomainTools, the Rugmi (also called Penguish) loader. The case matters because inexpensive criminal infrastructure can make even inexperienced operators dangerous.

The evidence shows infrastructure links and a delivery mechanism—not a verified real-world identity, a complete victim list or proof that Proton66 knowingly approved the activity.

What happened

  1. DomainTools identified a fraudulent antivirus site at cybersecureprotect[.]com.
  2. The site was hosted on or associated with the Proton66 ecosystem, which DomainTools and The Hacker News describe as Russian-based bulletproof hosting.
  3. An apparently enabled directory listing exposed staged files and scripts. That was an OPSEC failure: the reporting describes exposed infrastructure and linkage clues, not a confirmed compromise of Proton66 or a password/database breach.
  4. Researchers pivoted through domains, registration data, hosting, page content and other shared identifiers.
  5. Those pivots connected the operation to the alias Coquettte and the command-and-control domain cia[.]tf, registered with the address root@coquettte[.]com.

The primary narrative was reported by The Hacker News, based on DomainTools findings. A DomainTools recap explains the directory-listing mistake and the Proton66 context (podcast recap).

The observed delivery chain

The reported sequence separates the social-engineering lure from the loader and any final information stealer:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Stage What was reported What it does not prove
Fake site cybersecureprotect[.]com presented the product “Cyber Secure Pro.” That every site or file using a similar name belongs to this campaign.
Archive CyberSecure Pro.zip contained a Windows installer. That the archive itself was the final payload.
Installer The installer downloaded a second-stage payload. Exact installer behavior, hashes or persistence details; these were not published in the cited report.
Loader DomainTools associated the chain with Rugmi, also called Penguish. That every Rugmi operation has the same operator or victim set.
Possible stealers Rugmi has previously been linked to delivery of Lumma, Vidar and Raccoon. That Coquettte deployed all three in this operation.

Security branding is an effective pretext: a warning about infection makes an “antivirus” download feel urgent and legitimate. The archive and installer are delivery mechanisms; the reported historical associations with information stealers should not be read as confirmation of a particular payload in every infection.

How the infrastructure pivots exposed the operation

An open directory rarely proves an entire campaign by itself. Its value is that filenames, scripts, staging paths and other artifacts give investigators high-quality starting points. DomainTools combined those artifacts with relationship data to build an infrastructure graph.

Direct and strong technical clues

  • The exposed files and scripts on the fake-antivirus infrastructure.
  • The relationship between the site and Proton66-associated hosting.
  • The cia[.]tf C2 domain and the registration email root@coquettte[.]com.

Supporting correlations

  • Repeated registration details, nameservers, certificates, hosting locations or distinctive page elements.
  • Shared analytics identifiers, templates or naming conventions.
  • Historical DNS and passive-DNS relationships between apparently separate domains.

The evidentiary strength declines from direct server or malware artifacts, to repeated infrastructure correlations, to thematic similarity and analyst interpretation. Shared hosting alone is weak evidence: unrelated customers can occupy the same provider or address, and domains can be transferred, hijacked or resold.

Who is Coquettte?

Coquettte—spelled with three Ts, a spelling DomainTools says is intentional—is an alias attributed by DomainTools to an emerging actor. The public reporting portrays the operator as inexperienced, in part because an exposed directory and other reuse mistakes made the infrastructure easy to connect.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A personal website reportedly described its author as a 19-year-old software-development student. That is a self-description, not an independently verified age, identity, nationality or location. A pseudonymous profile can be fabricated, copied or operated by someone else.

The correct conclusion is therefore limited: DomainTools linked a set of infrastructure and activity to the Coquettte alias. It did not establish the person behind that alias.

What “bulletproof hosting” means here

“Bulletproof hosting” is a security-industry term for hosting arrangements unusually resistant to abuse complaints, takedown requests or termination. It is not a legal status and does not mean a provider is immune to seizure, sanctions, court orders or technical disruption.

DomainTools characterized Proton66 as a Russian provider or ecosystem associated with infrastructure used for malware and phishing. Three claims must remain separate:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Provider reputation: how researchers describe the network or its historical abuse profile.
  • Customer misuse: a particular customer used an address or service for malicious activity.
  • Provider intent: evidence that the provider knowingly facilitated or ignored that activity.

The Coquettte findings establish the second category for the reported infrastructure. They do not, on their own, establish the third.

The possible Horrid connection

DomainTools reported overlapping infrastructure that may indicate Coquettte was an alias used by one participant in a broader community calling itself Horrid. The public evidence does not establish a formal organization, command structure or that every associated site had one operator.

Websites linked in the reporting also offered guides concerning illegal-substance and weapons manufacture. That broadens the picture of an illicit ecosystem, but content similarity or shared hosting is not proof that the same person authored or controlled every site. “Possible affiliation” is the defensible description; labels such as a confirmed “Horrid gang” go beyond the evidence.

Indicators from the reported case

These are historical, defanged indicators from the April 2025 reporting. Do not visit them or distribute the archive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Type Indicator Qualification
Domain cybersecureprotect[.]com Fake-antivirus site reported by DomainTools.
Archive filename CyberSecure Pro.zip Filename observed in this investigation; not a universal campaign signature.
C2 domain cia[.]tf Infrastructure pivot reported by DomainTools.
Registration email root@coquettte[.]com Registration pivot linking the C2 domain to the alias.
ASN 198953 Proton66 identifier used in historical analysis.

DomainTools’ March 2024 report found an unusually concentrated malicious-activity profile for ASN 198953 in that snapshot. It is not a live reputation measurement or a basis for assuming that every address in the ASN is malicious today. See the historical report and its HTML edition.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Defensive lessons for enterprises

  • Block or investigate the reported domains and any validated hashes, while treating old indicators as leads rather than complete coverage.
  • Alert on newly registered domains using antivirus, security, update or protection language.
  • Inspect archives that contain installers, especially when downloaded from unsolicited advertisements, pop-ups or messages.
  • Use application control to prevent unsigned or untrusted installers from running.
  • Correlate DNS, proxy, endpoint, email and firewall telemetry; a single source rarely shows the whole chain.
  • Monitor outbound connections from newly installed software to recently registered or low-reputation domains.
  • Use passive-DNS and historical infrastructure data to pivot from a suspicious domain to related registrants, certificates, nameservers and hosting.

DomainTools documents capabilities for domain profiling, infrastructure pivots, historical DNS and risk context (product overview). A reputation score or relationship graph is a triage aid, not proof of criminal intent.

Incident-response checklist

  1. Isolate the endpoint suspected of running the installer.
  2. Preserve volatile evidence and endpoint logs before remediation.
  3. Record the original URL, redirects, archive, installer metadata and observed destinations.
  4. Collect DNS, proxy, firewall, EDR, email and browser telemetry.
  5. Search for related domains, certificates, filenames, hashes and process ancestry across the environment.
  6. If an information stealer may have run, reset credentials from a clean device, revoke active sessions and rotate tokens.
  7. Hunt for persistence, browser-data access, credential-store access and cryptocurrency-wallet access.
  8. Submit samples and validated indicators to trusted malware-analysis or threat-intelligence channels.
  9. Share confirmed indicators with relevant providers or national cyber-reporting mechanisms.

The public account does not provide a complete IOC package, malware hashes, exact installer behavior, persistence details or a full forensic timeline. Responders should not treat the news report as a substitute for collecting those facts from the affected endpoint.

Advice for individual users

  • Install security software only from the vendor’s verified website or the operating system’s official app ecosystem.
  • Do not run an installer merely because its filename says “security,” “protection” or “antivirus.”
  • If you ran a suspicious file, disconnect if practical, contact a trusted professional and change passwords from a separate clean device.
  • Enable multifactor authentication, especially for email, financial and password-manager accounts.
  • Assume stored browser passwords and active sessions may be exposed if an information stealer executed successfully.

What remains unknown

  • The actor’s verified legal identity, location and age.
  • The number and geography of victims.
  • Whether Lumma, Vidar, Raccoon or another payload was delivered in each infection.
  • The complete malware hashes, persistence behavior and forensic timeline.
  • The precise organizational relationship, if any, between Coquettte and Horrid.
  • Whether the reported infrastructure remained active after April 2025.

The enduring lesson is not that the operator displayed advanced tradecraft. It is that resilient hosting, commodity loaders and simple social engineering can let low-skill actors operate at a scale that defenders must still take seriously.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.