C&CMembers
C&C

Certificate-Recycling Pipeline Links 12 Domains Behind Weak Detection

Three Let's Encrypt and Google Trust Services CA intermediates tie together a scattered pool of gambling lures, aged domains, and a sinkholed relic. Two unrelated domains registered a year apart even converge on the same IP, revealing a hosting discipline that outpaces the campaign's near-invisible detection scores.

Jul 23, 2026, 13:34 (UTC+9)Last seenJul 23, 2026Severity100ByCTX TeamActorAPT15ROYALAPTIOC17MITRE6

Twelve domains, four IP addresses, and a single executable make up this cluster — and on the surface, they look unrelated: a decade-old Vietnamese-language domain, a pair of gambling lure pages using Indonesian togel slang, a 2016-registered relic now sitting on sinkhole nameservers, and a 221MB EV-signed installer called "Rave.exe." What ties them together isn't a shared malware family or a dedicated bulletproof host.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence