C&CMembers
C&C

APT28-Tagged Cluster Shows 89-Day Cert Pattern, No Malware

Three unrelated domains registered through different registrars share certificates valid for exactly 89 days, a signature of scripted provisioning rather than organic hosting. The cluster, tagged to APT28 with an espionage motivation, contains seven domains and five IPs but zero malware samples — pointing to staging infrastructure built ahead of a delivery wave.

Aug 3, 2026, 05:32 (UTC+9)Last seenAug 3, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC12MITRE4

Three domains with nothing else in common — different registrars, different creation dates, different Let's Encrypt intermediates — share one oddly precise trait: certificates valid for exactly 89 days. ccu.to, swisscutterastronaut.com, and each-task.com were issued certificates by three separate Let's Encrypt intermediates (R13, YR2, and YE1, respectively), yet all three validity windows run to the same 89-day span.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence