Dear localhost.run team,
We are currently involved in an active criminal fraud investigation (China, Case No. Yugong (Crim) [2026] 780).
A subdomain under your service:
a3039459fd4dc7.lhr.life
has been identified as part of a command-and-control infrastructure used in a mobile banking trojan attack.
We have already contacted abuse@localhost.run but have not yet received a response.
Due to the short retention period of connection logs, we urgently request your assistance in preserving relevant logs (SSH source IP, timestamps) for:
- May 18, 2026
- July 21, 2026
Official law enforcement requests will follow.
We would greatly appreciate your acknowledgement.
Thank you for your support in combating cybercrime.
Dear localhost.run team,
We are currently involved in an active criminal fraud investigation (China, Case No. Yugong (Crim) [2026] 780).
A subdomain under your service:
a3039459fd4dc7.lhr.life
has been identified as part of a command-and-control infrastructure used in a mobile banking trojan attack.
We have already contacted abuse@localhost.run but have not yet received a response.
Due to the short retention period of connection logs, we urgently request your assistance in preserving relevant logs (SSH source IP, timestamps) for:
Official law enforcement requests will follow.
We would greatly appreciate your acknowledgement.
Thank you for your support in combating cybercrime.