
APT28-Tagged Cluster Shows 89-Day Cert Pattern, No Malware
Three unrelated domains registered through different registrars share certificates valid for exactly 89 days, a signature of scripted provisioning rather than organic hosting. The cluster, tagged to APT28 with an espionage motivation, contains seven domains and five IPs but zero malware samples — pointing to staging infrastructure built ahead of a delivery wave.
Three domains with nothing else in common — different registrars, different creation dates, different Let's Encrypt intermediates — share one oddly precise trait: certificates valid for exactly 89 days. ccu.to, swisscutterastronaut.com, and each-task.com were issued certificates by three separate Let's Encrypt intermediates (R13, YR2, and YE1, respectively), yet all three validity windows run to the same 89-day span.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read