
Emotet Hijacks Aged German Sites to Evade Detection in PNG Campaign
Four German-hosted websites, some registered as far back as 2000, are serving as Emotet payload-distribution nodes targeting Papua New Guinea's hospitality sector. Operators re-armed two domains with fresh TLS certificates months before the campaign, exploiting decades of domain-age reputation to stay below network-layer detection thresholds.
Four German-hosted websites — three of them registered between 2000 and 2009, all of them delegating DNS through the same Cronon/Strato nameserver infrastructure — are serving as the distribution backbone for an active Emotet campaign targeting the hospitality sector in Papua New Guinea. The cluster, observed by CTX Team between 14 and 21 June 2026, is analytically notable not for the malware it delivers but for the hosting architecture it exploits: rather than spinning up fresh…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read