APTMembers
APT

Disposable Storefronts Share One DNS Backbone Behind GCleaner Loaders

Three fake e-commerce domains resolve through identical Dynadot nameservers and share Let's Encrypt certificate patterns, pointing to one operator cycling disposable storefronts rather than three unrelated campaigns. A recurring 89-day certificate lifespan across three different CAs ties the domains to broader loader infrastructure feeding GCleaner-branded droppers.

Aug 28, 2026, 22:31 (UTC+9)Last seenAug 28, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC30MITRE23

Three domains dressed up as e-commerce storefronts — shhsift.click, kupzovo.shop, and vexdico.shop — resolve through the identical nameserver pair ns1.dyna-ns.net and ns2.dyna-ns.net, the Dynadot-operated DNS infrastructure that sits behind all three registrations. That is not three operators independently choosing the same registrar; it is the same DNS footprint appearing on domains with unrelated naming conventions and different final IP addresses (159.65.136.5, 66.228.41.52, and…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence