APTMembers
APT

Same-Day Certificates Expose Scripted C2 Build-Out Behind Two Trojans

A cluster of five domains, four IPs and two Windows droppers shares a same-day Let's Encrypt certificate pattern, a NICENIC registrar cohort, and a cert-serial match tying a fresh domain to its live hosting IP. The payloads are generic signed-but-untrusted installers — the real signature is how fast the infrastructure was assembled.

Jun 11, 2026, 14:40 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC22RegionsIDMYPL

Three infrastructure nodes — the IPs 31.58.134.74 and 80.97.160.31, plus the freshly minted domain powershell-storage.vg — received Let's Encrypt certificates from the same "YE2" intermediate within a two-day window in June, each carrying an identical 89-day validity span. That kind of synchronized issuance is not how organically managed hosting behaves; it is what scripted infrastructure provisioning looks like when an operator wants a C2 front live and disposable within hours of registering…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence