C&CMembers
C&C

A Redirect Node With No Name: Certificate Cycling Masks a 2014 Dropper

A domain buried in a routine C2 record serves a certificate for a hostname no one requested, exposing it as a relay in a shared hosting fabric rather than an independent site. Sixteen domains and three scattered IPs turn out to be linked not by malware code but by the rhythm of Let's Encrypt certificate reissuance.

Sep 13, 2026, 22:30 (UTC+9)Last seenSep 13, 2026Severity100ByCTX TeamIOC36MITRE23RegionsGBRO

A domain buried inside a routine C2-infrastructure record — baktus.kilu.de — is not serving its own website. Query it over TLS and the certificate that comes back carries the subject name redirect.subdomain.com, a string that points nowhere near the domain a browser actually requested. That mismatch is the clearest single artefact in this record: it marks the node as a relay hop inside a shared hosting fabric, not an independent site with its own identity.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence