Alpha Cyber

Unmasking GodLua: A Glimpse into Malware’s Hidden Infrastructure

Unveiling the GodLua DNS over HTTPS Malware Infrastructure In today’s rapidly evolving cyber threat landscape, GodLua DNS over HTTPS (DoH) malware stands out as a sophisticated and stealthy adversary.

Alpha Cyber Research1 min readupdated 1 Apr 2026
GodLua Graph

Unveiling the GodLua DNS over HTTPS Malware Infrastructure 

In today’s rapidly evolving cyber threat landscape, GodLua DNS over HTTPS (DoH) malware stands out as a sophisticated and stealthy adversary. This malware leverages the encrypted DoH protocol to communicate covertly with its command-and-control (C&C) servers, making it difficult for traditional security tools to detect and block.

At Alpha Cyber, we harness the power of analysis tools, a cutting-edge threat intelligence and visualization tool, to map the complex infrastructure behind GodLua. Using advanced data mining tools and link analysis capabilities, we uncover the network of malicious domains, IP addresses, and C&C servers that GodLua uses to operate undetected.

Why Mapping GodLua’s Infrastructure Matters

Visualize Threat Networks: interactive graphs reveal how GodLua’s components interconnect, exposing hidden relationships and infection vectors.

Enhance Detection: Identifying malicious domains and servers helps organizations proactively block threats before they cause damage.

Strengthen Defense: Understanding the malware’s infrastructure empowers your security team to implement targeted countermeasures and reduce risk.

Protect Your Business from Emerging Threats
GodLua’s use of DNS over HTTPS allows it to bypass many perimeter defenses, increasing the risk of data breaches and service disruptions. By leveraging  infrastructure mapping tools, we provide actionable intelligence that keeps your network one step ahead of attackers.

Don’t let advanced malware exploit your blind spots. Contact Alpha Cyber today to learn how our threat intelligence and endpoint security services can safeguard your business from GodLua and other emerging threats. Secure your future with expert cybersecurity solutions tailored to today’s challenges.

IOCS:

Command-and-Control server IP

104.238.151.101

Hardcoded C2 domains

d.heheda.tk 
c.heheda.tk 
dd.heheda.tk

Additional C2 domain
c.cloudappconfig.com 

Associated Rocke group domain
sowcar.com 
z9ls.com 
baocangwh.cn 
gwjyhs.com
w2wz.cn 

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]