APTMembers
APT

Decade-Old Self-Signed Certificate Ties FIN7 Infrastructure Together

A self-signed TLS certificate minted in October 2015 still links three domains registered years apart, including two now sinkholed. A fourth, freshly-registered domain hidden behind Cloudflare carries no shared certificate or IP — only the same beacon path, /new/stats.php.

Jul 21, 2026, 05:34 (UTC+9)Last seenJul 21, 2026Severity100ByCTX TeamActorFIN7Gold NiagaraIOC14MITRE21

A self-signed TLS certificate stamped "localhost.localdomain" and valid for exactly one year beginning in October 2015 is still doing operational work more than a decade later. Three domains — diamonddollsfitness.com, mastering-the-art-of.com, and lf7blogpro.com — present the byte-identical certificate, serial cfddb89f9d1426ad, and all three resolve to the same IP address, 184.105.192.2.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence