Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is infrastructure rotation?

Infrastructure rotation replaces domains, addresses, servers or accounts to avoid blocking, restore capacity or respond to detection. A new address does not necessarily mean a new offender or campaign.

Test continuity across the change

Compare malware configuration, certificates, provider accounts, access sources, payment, images, protocols, naming and victim behaviour. Several independent links carry more weight than nearby addresses or similar names.

Historical DNS, certificates and provider records can show creation, deployment, suspension and replacement that current hosting hides.

Separate preparation from operation

Fallback domains and pre-created accounts may be prepared but never used. Report configuration or registration separately from observed victim contact.

A replacement appearing immediately after blocking, used by the same process and configuration, can support operational continuity. Ordinary provider failover and unrelated shared-service reuse remain alternatives to test.

Key takeaway

Establish infrastructure rotation through multiple historical technical and provider links, distinguishing prepared resources, observed use and unrelated reuse.

Reference: CIM-251Cyber Incidents & Offender Methods