APTMembers
APT

Emotet Revives 18-Year-Old Domains in Coordinated Chile Campaign

Three .com domains registered between 2007 and 2008 were reactivated with fresh Let's Encrypt certificates across a 17-day window in April–May 2026, serving as payload-staging and C2 nodes for an Emotet-linked campaign targeting Chile. The coordinated provisioning exploits historical domain reputation to defeat age-based URL-filtering controls, while Cloudflare proxying and shared-hosting compromise frustrate passive attribution.

May 29, 2026, 10:04 (UTC+9)Last seenMay 29, 2026Severity92ByCTX TeamActorEmotet GroupTA542IOC14RegionsCL

Three .com domains registered between November 2007 and January 2008 — old enough to predate the iPhone's first software update cycle — have been quietly reactivated as payload-staging and command-and-control nodes for an Emotet-linked campaign targeting Chile. The reactivation was not gradual. Between 17 April and 4 May 2026, all three domains received fresh 89-day Let's Encrypt certificates within a compressed 17-day window, a coordinated provisioning pass that CTX Team's analysis identifies…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence