Skip to content
Cybersecurity

Tracking Adversary Infrastructure With Censys Data

/ 12 min read / Malik Tanveer Dhool

Adversary infrastructure — the C2 servers, phishing kits, and malware staging behind every attack — can be mapped from a single clue using internet intelligence. This guide shows how researchers do it, with real published cases.

← Back to Blog
Share X in

WarBrief Live | October 6, 2026 | Cyber Intelligence

Every cyberattack needs a backstage: the servers, domains, and certificates that threat actors use to send stolen data home, trick victims, and hand out malware. Security researchers call this adversary infrastructure, and learning to track it is one of the most valuable skills in modern defense. Platforms that scan the entire internet have made this work possible at scale. Tracking Censys adversary infrastructure data — the records of every internet-connected server, service, and certificate that Censys collects — lets defenders map an attacker’s hidden network from a single starting clue.

This guide explains what adversary infrastructure is, how researchers follow it from one indicator to a whole campaign, and what real published investigations have exposed.

Key Takeaways

  • Adversary infrastructure covers command-and-control servers, phishing kits, malware delivery networks, and the domains, IPs, and certificates tying them together.
  • Researchers track it through pivoting: certificate transparency, TLS fingerprints, favicon hashes, and passive DNS links turn one indicator into a whole cluster.
  • Published cases show real results — a single fake TLS certificate exposed 68 Cobalt Strike servers, and historical scan data mapped a botnet’s adjacent infrastructure.
  • Defenders use infrastructure intelligence to block attacks early, but must work passively so they never tip off the operator.

What Does Adversary Infrastructure Actually Include?

Think of a spy ring’s safe houses. The agents move, but the safe houses have addresses, phones, and landlords — and anyone who finds one safe house can watch it to find the next. Adversary infrastructure works the same way: it is the internet-facing equipment and services a threat actor relies on, and it is far easier to track than the people behind it.

Command-and-Control Infrastructure

Command-and-control (C2) infrastructure is the system that lets an attacker stay in contact with infected computers. A C2 server receives stolen data, sends new instructions, and coordinates the compromised machines like a switchboard. Well-known C2 frameworks include Cobalt Strike, Mythic, Sliver, and Havoc — tools originally built for legitimate security testing that criminals and state actors routinely abuse.

C2 servers are the beating heart of most campaigns. When defenders identify one, they can cut off the attacker’s hands from the brain — which is why tracking C2 infrastructure is a top priority for threat intelligence teams.

Phishing Infrastructure

Phishing infrastructure covers the fake login pages, lookalike domains, and phishing kits actors deploy to steal credentials. Modern phishing-as-a-service operations run like businesses, templating dozens of brand-impersonation domains from one kit. The infrastructure often shares fingerprints: the same TLS certificates, the same hosting provider, or identical page layouts across domains that otherwise look unrelated.

Malware Delivery Infrastructure

Malware delivery infrastructure hosts the malicious payloads themselves — the files victims download, often served through FTP, web servers, or open directories. Because operators reuse staging servers across campaigns, researchers can sometimes find a current campaign’s payloads sitting on a server that hosted older ones, revealing the operation’s history.

These three layers rarely exist in isolation. The domain that hosts the phishing page, the server that delivers the malware, and the C2 that receives the data are often connected through shared certificates, shared IP ranges, or shared registration patterns. Finding one connection gives researchers a thread to pull — and that is where pivoting begins. (For more on how the underlying internet data is collected, see CensysInspect Explained: Internet Intelligence Guide and our guide to internet-wide scan data.)

How Researchers Map Censys Adversary Infrastructure

Internet intelligence platforms work by continuously scanning every public IP address and recording what they find: open ports, services, banners, and TLS certificates. Censys, for example, scans all 65,535 ports across more than 200 protocols and keeps historical snapshots of every internet-connected asset. That history is the investigator’s time machine — it shows what a server looked like months before it was reported as malicious.

From a single seed indicator, researchers pivot outward through passive datasets. A typical pivot chain runs like this: a phishing domain’s historical DNS records reveal the IPs it resolved to; certificate transparency logs show the other hostnames sharing its TLS certificate; the IP’s TLS handshake fingerprint (JARM or JA3) matches known malicious defaults; the server’s favicon hash finds other servers running the identical control panel. One indicator becomes a cluster, and none of it required touching the adversary.

Censys’s own tooling is built for this. Its Investigation Manager lets analysts build node-based pivot maps of related infrastructure, and its contextual-hash search lets researchers take a rare attribute — an unusual HTTP header, a distinctive TLS value — and instantly see how many other hosts on the internet share it. CensEye, another feature, extracts rare high-signal attributes to surface hidden related infrastructure. None of this requires interacting with the live malicious server.

Discipline matters here. Good investigators follow a strict rule: never tip off the adversary. Never connect to a live C2 from your own network, resolve its domain through attributable systems, upload an active sample to a public scanner, or scan the infrastructure directly. Each of those actions tells the operator they are being watched — and they will rotate their infrastructure and vanish. The rule is simple: observe from the records, never poke the live thing. (Our comparison of scanning platforms for threat hunting, Censys vs Shodan for Threat Hunting Teams Compared (2026), covers the tradecraft in more depth.)

AI-generated illustration

Can a Single Certificate Expose an Entire Campaign?

Yes — and published research proves it. In a widely cited blog post, Censys researchers demonstrated hunting for Cobalt Strike servers by their TLS certificates. Cobalt Strike lets operators generate a self-signed certificate from a configurable profile, and when operators use default or shared profiles, the certificates carry recognizable fingerprints. One fake certificate — claiming to be for “jquery.com” with empty state and location fields, generated by a public jQuery-themed profile — appeared on 68 distinct hosts in Censys’s data. Every single one of them was already flagged as running Cobalt Strike. That is not a coincidence; it is certificate pivoting turning one pattern into dozens of exposed servers.

The same technique works on other frameworks. In September 2026, Censys researchers mapped Mythic C2 deployments at internet scale by their default fingerprints: self-signed certificates with subjects like O=Mythic or O=Mythic C2, plus a default internal PKI chain of CN=operators issuing a CN=multiplayer server certificate. The researchers found 98 hosts carrying O=Mythic and 21 carrying O=Mythic C2 — and several of those hosts also exposed other frameworks like Sliver, Adaptix C2, or Havoc, suggesting shared tooling among operators. (Our broader look at how attacks are investigated, How Internet Intelligence Helps Investigate Cyber Attacks, shows where this kind of pivoting fits in a full investigation.)

Historical data adds another dimension. In Censys’s 2025 State of the Internet report, researchers took a host identified by Sekoia as a PolarEdge botnet payload-distribution server — the IP 119.8.186[.]227, a Huawei Cloud address in Singapore — and used historical scans to look back to February 2025, when the attacker activity began. The host was exposing unusual TLS services with suspicious certificates, including one tied to the domain www[.]learningrtc[.]cn. Tracing that certificate led to a GitHub repository containing an exact match that appeared to be a test certificate from a legitimate project — a reminder that pivoting surfaces leads, and analysts must separate attacker artifacts from coincidence.

“The attacker used the IP address 119.8.186[.]227 to distribute these payloads via FTP. This address is located in Singapore and belongs to Huawei Cloud. Based on a Censys search, several non-standard TCP ports are open, exposing TLS services associated with either suspicious certificates or those linked to Polar.” — Sekoia Research Team, cited in Censys’s State of the Internet 2025 report

Why Do Threat Actors Keep Reusing Infrastructure?

Operators recycle infrastructure for the same reason criminals reuse cars: it is expensive to build everything from scratch, and the old setup works. Researchers have documented this reuse across both cybercriminal and nation-state operations, and it is one of the most productive sources of intelligence.

One example comes from Censys’s investigation of NTC Vulkan, a Russian company whose servers researchers examined through historical host data to understand an organization believed to be developing tools for the GRU’s Sandworm unit. Because the historical record survived the operators’ later changes, investigators could reconstruct what the servers did and how the organization functioned — context that would have been invisible from the present day alone.

Cisco Talos has shown how even careful ransomware gangs leave infrastructure trails. Researchers traced the TLS certificates of dark-web leak sites back to their hosting providers — for the DarkAngels operation, believed to be a rebrand of the Babuk ransomware group, the trail ultimately yielded private keys and an operator login portal. For the Quantum group, Talos used favicon matching — finding other servers serving the identical tiny icon — to trace the gang’s hosting and associated domains. The criminals’ own certificates pointed back to them.

Certificate reuse is a classic mistake. Cisco Talos’s “Sea Turtle” report documented a DNS-hijacking campaign that used Let’s Encrypt certificates on its man-in-the-middle servers and even stole victims’ legitimate SSL certificates, reusing them on servers it controlled.

But researchers also warn that infrastructure is getting harder to trust. Mandiant reported in September 2025 that Chinese threat actors are hiding behind “ORB” networks — operational relay boxes, vast webs of virtual private servers and compromised smart devices and routers that conceal the true source of attacks. Because multiple threat actors can use the same ORB network simultaneously, even egressing from the same IP addresses, a single IP no longer reliably identifies one actor.

“What you’re dealing with, as an enterprise, is the professionalization of infrastructure-as-a-service. It’s no longer [the case that] if you see a threat actor utilizing a single IP, that we can attribute that activity to a single threat actor. Instead, all we’re really able to say is this threat actor is using this support network in this time period.” — Michael Raggi, principal analyst with Mandiant by Google Cloud

This is why analysts treat shared infrastructure as a lead, not a conclusion — one IP no longer proves one actor, and every pivot demands independent confirmation before it becomes attribution. (For a nation-state example of infrastructure tracking across a real conflict, see Russia-Ukraine Cyber War: Tracking Digital Infrastructure.)

AI-generated illustration

How Defenders Turn Infrastructure Intelligence Into Protection

Tracking adversary infrastructure is only useful if it becomes action. Defenders use infrastructure intelligence in several concrete ways. First, blocking: when a research team publishes a cluster of malicious domains, IPs, and certificate fingerprints, firewalls, DNS filters, and email gateways can block the whole cluster at once — not just the one server that was reported. Second, early warning: historical data shows when an operator registers lookalike domains or stands up new servers, letting defenders block phishing infrastructure before the first email is sent. Third, incident response: when a breach is discovered, investigators check whether the attacker’s infrastructure touched other systems in their environment, expanding the scope of the cleanup.

This work is increasingly automated. Censys formalized its research arm as the Censys Advanced Research Collective (ARC) in March 2026, a team that tracks threat infrastructure and high-risk exposures — including work that has linked malicious infrastructure to nation-state actors and mapped global malware campaigns. Its curated adversary investigations dataset tracks reuse patterns for groups including MuddyWater, Sandworm, Volt Typhoon, Lazarus, and APT28, with evidence tied to direct scans of the endpoints. Cisco Talos has similarly open-sourced tools like CAIRN, which pivots through metadata graphs to surface shared domains, IP addresses, certificates, and C2 servers behind malware samples.

For security teams, the workflow is straightforward: subscribe to reputable threat feeds, enrich alerts with internet-scan context (what is this IP, what certificate does it serve, what else shares it?), and hunt proactively for published fingerprints — default TLS values, unusual certificate patterns, known C2 banners. The Diamond Model of intrusion analysis formalizes this: every intrusion has four connected features — adversary, capability, infrastructure, and victim — and pivoting is simply traversing the edges between them, so a partial picture from one investigation composes with the next.

For a deeper grounding, read our guide to how internet scanning exposed infrastructure in conflict zones, our explainer on what Censys Inspect is, and the research-methods primer Cyber Warfare Research: Using Internet Scan Data (2026).

Frequently asked questions

What is adversary infrastructure?
Adversary infrastructure is the internet-facing equipment and services threat actors rely on: command-and-control servers, phishing pages and kits, malware staging servers, and the domains, IP addresses, and certificates connecting them. Tracking it lets defenders find and block an attacker’s operations without needing to identify the people behind them.

How does Censys data help track threat actor infrastructure?
Censys continuously scans every public IP address across all 65,535 ports and keeps historical snapshots of what it finds — services, banners, and TLS certificates. Researchers pivot from a single indicator through certificate transparency records, TLS fingerprints, and passive DNS to map whole clusters of related servers, all without touching the live malicious infrastructure.

Can TLS certificates really expose attacker infrastructure?
Yes. Published cases include a single fake “jquery.com” certificate pattern appearing on 68 Cobalt Strike servers, default Mythic C2 certificates revealing over a hundred deployments, and Cisco Talos tracing ransomware gangs’ dark-web leak sites back to their hosting providers through certificate reuse.

Is tracking adversary infrastructure legal and ethical?
Yes, when done defensively through public and passive data sources — scan records, certificate transparency logs, and published threat reports. Responsible researchers never interact with live malicious infrastructure, because probing it alerts the operator and can constitute unauthorized access.

What should defenders do with infrastructure intelligence?
Block the full cluster of related indicators in firewalls and DNS filters, hunt for published fingerprints in your own environment, and use historical data to spot new infrastructure before campaigns launch. Sharing findings with trusted threat-intelligence communities multiplies the value.

Conclusion

Adversary infrastructure is the trail every attacker leaves behind. Servers, certificates, and domains can be rotated, but reuse patterns — the shared certificate, the familiar handshake fingerprint, the historical scan footprint — keep betraying operators across campaigns. From a single fake TLS certificate exposing 68 Cobalt Strike servers to researchers reconstructing a GRU-linked developer’s servers from history, the published record shows that internet-scale visibility has made hiding in the noise much harder.

The craft has its limits: shared relay networks and professionalized infrastructure services mean a single IP no longer proves a single actor, and every pivot demands independent confirmation before it becomes attribution. But as a defensive discipline, infrastructure tracking turns scattered attack reports into connected maps — and connected maps let defenders block not just one attack, but the machinery behind the next one.

Sources and Further Reading

Written by

Malik Tanveer Dhool

Defense and intelligence analysis for WarBrief.live. Covering conflict, technology, and geopolitical strategy.