APTMembers
APT

Donot Team Ties Three Domain Clusters via 89-Day Cert Cadence

Five domains spanning a Thai medical-software vendor's subdomains, an AWS Route53/Panama-fronted delivery node, and a hijacked 2018 Japanese domain share no registrar, IP, or owner — yet all rotate identical 89-day Let's Encrypt certificates. Researchers say the pattern points to a centralized, scripted provisioning pipeline behind an APTC35/Donot Team espionage campaign targeting government, healthcare, and telecom targets.

Aug 4, 2026, 05:33 (UTC+9)Last seenAug 4, 2026Severity100ByCTX TeamActorAPTC35Donot TeamIOC27MITRE18

Five domains, three registrars, three continents' worth of WHOIS geography, and not a single shared owner on paper — yet every one of them carries an identical 89-day Let's Encrypt certificate validity window. That convergence, surfaced across a Thai medical-software vendor's subdomain fleet, an AWS Route53-fronted delivery node registered through a Panama privacy proxy, and a decade-old Japanese domain flagged for compromise, is the strongest signal in this indicator set — stronger, in fact,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence