
Donot Team Ties Three Domain Clusters via 89-Day Cert Cadence
Five domains spanning a Thai medical-software vendor's subdomains, an AWS Route53/Panama-fronted delivery node, and a hijacked 2018 Japanese domain share no registrar, IP, or owner — yet all rotate identical 89-day Let's Encrypt certificates. Researchers say the pattern points to a centralized, scripted provisioning pipeline behind an APTC35/Donot Team espionage campaign targeting government, healthcare, and telecom targets.
Five domains, three registrars, three continents' worth of WHOIS geography, and not a single shared owner on paper — yet every one of them carries an identical 89-day Let's Encrypt certificate validity window. That convergence, surfaced across a Thai medical-software vendor's subdomain fleet, an AWS Route53-fronted delivery node registered through a Panama privacy proxy, and a decade-old Japanese domain flagged for compromise, is the strongest signal in this indicator set — stronger, in fact,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read