An exposed directory helped DomainTools connect a fake antivirus website, Proton66-associated infrastructure and a malware-delivery operation attributed to the emerging actor Coquettte. The April 4, 2025 report describes a chain that used the Cyber Secure Pro lure to deliver a Windows installer and, according to DomainTools, the Rugmi (also called Penguish) loader. The case matters because inexpensive criminal infrastructure can make even inexperienced operators dangerous.
The evidence shows infrastructure links and a delivery mechanism—not a verified real-world identity, a complete victim list or proof that Proton66 knowingly approved the activity.
What happened
- DomainTools identified a fraudulent antivirus site at
cybersecureprotect[.]com. - The site was hosted on or associated with the Proton66 ecosystem, which DomainTools and The Hacker News describe as Russian-based bulletproof hosting.
- An apparently enabled directory listing exposed staged files and scripts. That was an OPSEC failure: the reporting describes exposed infrastructure and linkage clues, not a confirmed compromise of Proton66 or a password/database breach.
- Researchers pivoted through domains, registration data, hosting, page content and other shared identifiers.
- Those pivots connected the operation to the alias Coquettte and the command-and-control domain
cia[.]tf, registered with the addressroot@coquettte[.]com.
The primary narrative was reported by The Hacker News, based on DomainTools findings. A DomainTools recap explains the directory-listing mistake and the Proton66 context (podcast recap).
The observed delivery chain
The reported sequence separates the social-engineering lure from the loader and any final information stealer:
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
| Stage | What was reported | What it does not prove |
|---|---|---|
| Fake site | cybersecureprotect[.]com presented the product “Cyber Secure Pro.” |
That every site or file using a similar name belongs to this campaign. |
| Archive | CyberSecure Pro.zip contained a Windows installer. |
That the archive itself was the final payload. |
| Installer | The installer downloaded a second-stage payload. | Exact installer behavior, hashes or persistence details; these were not published in the cited report. |
| Loader | DomainTools associated the chain with Rugmi, also called Penguish. | That every Rugmi operation has the same operator or victim set. |
| Possible stealers | Rugmi has previously been linked to delivery of Lumma, Vidar and Raccoon. | That Coquettte deployed all three in this operation. |
Security branding is an effective pretext: a warning about infection makes an “antivirus” download feel urgent and legitimate. The archive and installer are delivery mechanisms; the reported historical associations with information stealers should not be read as confirmation of a particular payload in every infection.
How the infrastructure pivots exposed the operation
An open directory rarely proves an entire campaign by itself. Its value is that filenames, scripts, staging paths and other artifacts give investigators high-quality starting points. DomainTools combined those artifacts with relationship data to build an infrastructure graph.
Direct and strong technical clues
- The exposed files and scripts on the fake-antivirus infrastructure.
- The relationship between the site and Proton66-associated hosting.
- The
cia[.]tfC2 domain and the registration emailroot@coquettte[.]com.
Supporting correlations
- Repeated registration details, nameservers, certificates, hosting locations or distinctive page elements.
- Shared analytics identifiers, templates or naming conventions.
- Historical DNS and passive-DNS relationships between apparently separate domains.
The evidentiary strength declines from direct server or malware artifacts, to repeated infrastructure correlations, to thematic similarity and analyst interpretation. Shared hosting alone is weak evidence: unrelated customers can occupy the same provider or address, and domains can be transferred, hijacked or resold.
Rank #2
Who is Coquettte?
Coquettte—spelled with three Ts, a spelling DomainTools says is intentional—is an alias attributed by DomainTools to an emerging actor. The public reporting portrays the operator as inexperienced, in part because an exposed directory and other reuse mistakes made the infrastructure easy to connect.
Free tools Windows power users keep installed
One-click scans. No signup required.
A personal website reportedly described its author as a 19-year-old software-development student. That is a self-description, not an independently verified age, identity, nationality or location. A pseudonymous profile can be fabricated, copied or operated by someone else.
The correct conclusion is therefore limited: DomainTools linked a set of infrastructure and activity to the Coquettte alias. It did not establish the person behind that alias.
Rank #3
What “bulletproof hosting” means here
“Bulletproof hosting” is a security-industry term for hosting arrangements unusually resistant to abuse complaints, takedown requests or termination. It is not a legal status and does not mean a provider is immune to seizure, sanctions, court orders or technical disruption.
DomainTools characterized Proton66 as a Russian provider or ecosystem associated with infrastructure used for malware and phishing. Three claims must remain separate:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute- Provider reputation: how researchers describe the network or its historical abuse profile.
- Customer misuse: a particular customer used an address or service for malicious activity.
- Provider intent: evidence that the provider knowingly facilitated or ignored that activity.
The Coquettte findings establish the second category for the reported infrastructure. They do not, on their own, establish the third.
The possible Horrid connection
DomainTools reported overlapping infrastructure that may indicate Coquettte was an alias used by one participant in a broader community calling itself Horrid. The public evidence does not establish a formal organization, command structure or that every associated site had one operator.
Websites linked in the reporting also offered guides concerning illegal-substance and weapons manufacture. That broadens the picture of an illicit ecosystem, but content similarity or shared hosting is not proof that the same person authored or controlled every site. “Possible affiliation” is the defensible description; labels such as a confirmed “Horrid gang” go beyond the evidence.
Indicators from the reported case
These are historical, defanged indicators from the April 2025 reporting. Do not visit them or distribute the archive.
Best Value
| Type | Indicator | Qualification |
|---|---|---|
| Domain | cybersecureprotect[.]com |
Fake-antivirus site reported by DomainTools. |
| Archive filename | CyberSecure Pro.zip |
Filename observed in this investigation; not a universal campaign signature. |
| C2 domain | cia[.]tf |
Infrastructure pivot reported by DomainTools. |
| Registration email | root@coquettte[.]com |
Registration pivot linking the C2 domain to the alias. |
| ASN | 198953 | Proton66 identifier used in historical analysis. |
DomainTools’ March 2024 report found an unusually concentrated malicious-activity profile for ASN 198953 in that snapshot. It is not a live reputation measurement or a basis for assuming that every address in the ASN is malicious today. See the historical report and its HTML edition.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Defensive lessons for enterprises
- Block or investigate the reported domains and any validated hashes, while treating old indicators as leads rather than complete coverage.
- Alert on newly registered domains using antivirus, security, update or protection language.
- Inspect archives that contain installers, especially when downloaded from unsolicited advertisements, pop-ups or messages.
- Use application control to prevent unsigned or untrusted installers from running.
- Correlate DNS, proxy, endpoint, email and firewall telemetry; a single source rarely shows the whole chain.
- Monitor outbound connections from newly installed software to recently registered or low-reputation domains.
- Use passive-DNS and historical infrastructure data to pivot from a suspicious domain to related registrants, certificates, nameservers and hosting.
DomainTools documents capabilities for domain profiling, infrastructure pivots, historical DNS and risk context (product overview). A reputation score or relationship graph is a triage aid, not proof of criminal intent.
Incident-response checklist
- Isolate the endpoint suspected of running the installer.
- Preserve volatile evidence and endpoint logs before remediation.
- Record the original URL, redirects, archive, installer metadata and observed destinations.
- Collect DNS, proxy, firewall, EDR, email and browser telemetry.
- Search for related domains, certificates, filenames, hashes and process ancestry across the environment.
- If an information stealer may have run, reset credentials from a clean device, revoke active sessions and rotate tokens.
- Hunt for persistence, browser-data access, credential-store access and cryptocurrency-wallet access.
- Submit samples and validated indicators to trusted malware-analysis or threat-intelligence channels.
- Share confirmed indicators with relevant providers or national cyber-reporting mechanisms.
The public account does not provide a complete IOC package, malware hashes, exact installer behavior, persistence details or a full forensic timeline. Responders should not treat the news report as a substitute for collecting those facts from the affected endpoint.
Advice for individual users
- Install security software only from the vendor’s verified website or the operating system’s official app ecosystem.
- Do not run an installer merely because its filename says “security,” “protection” or “antivirus.”
- If you ran a suspicious file, disconnect if practical, contact a trusted professional and change passwords from a separate clean device.
- Enable multifactor authentication, especially for email, financial and password-manager accounts.
- Assume stored browser passwords and active sessions may be exposed if an information stealer executed successfully.
What remains unknown
- The actor’s verified legal identity, location and age.
- The number and geography of victims.
- Whether Lumma, Vidar, Raccoon or another payload was delivered in each infection.
- The complete malware hashes, persistence behavior and forensic timeline.
- The precise organizational relationship, if any, between Coquettte and Horrid.
- Whether the reported infrastructure remained active after April 2025.
The enduring lesson is not that the operator displayed advanced tradecraft. It is that resilient hosting, commodity loaders and simple social engineering can let low-skill actors operate at a scale that defenders must still take seriously.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




