
Emotet Revives 18-Year-Old Domains in Coordinated Chile Campaign
Three .com domains registered between 2007 and 2008 were reactivated with fresh Let's Encrypt certificates across a 17-day window in April–May 2026, serving as payload-staging and C2 nodes for an Emotet-linked campaign targeting Chile. The coordinated provisioning exploits historical domain reputation to defeat age-based URL-filtering controls, while Cloudflare proxying and shared-hosting compromise frustrate passive attribution.
Three .com domains registered between November 2007 and January 2008 — old enough to predate the iPhone's first software update cycle — have been quietly reactivated as payload-staging and command-and-control nodes for an Emotet-linked campaign targeting Chile. The reactivation was not gradual. Between 17 April and 4 May 2026, all three domains received fresh 89-day Let's Encrypt certificates within a compressed 17-day window, a coordinated provisioning pass that CTX Team's analysis identifies…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read