What is infrastructure rotation?¶
Infrastructure rotation replaces domains, addresses, servers or accounts to avoid blocking, restore capacity or respond to detection. A new address does not necessarily mean a new offender or campaign.
Test continuity across the change¶
Compare malware configuration, certificates, provider accounts, access sources, payment, images, protocols, naming and victim behaviour. Several independent links carry more weight than nearby addresses or similar names.
Historical DNS, certificates and provider records can show creation, deployment, suspension and replacement that current hosting hides.
Separate preparation from operation¶
Fallback domains and pre-created accounts may be prepared but never used. Report configuration or registration separately from observed victim contact.
A replacement appearing immediately after blocking, used by the same process and configuration, can support operational continuity. Ordinary provider failover and unrelated shared-service reuse remain alternatives to test.
Key takeaway
Establish infrastructure rotation through multiple historical technical and provider links, distinguishing prepared resources, observed use and unrelated reuse.