
Dormant Domain Reactivated With Fresh Cert to Power Backdoor C2
A domain registered in 2019 and parked for six years suddenly received a new 89-day Let's Encrypt certificate in September 2025, then began hosting randomized check-in paths under a live-looking subdomain. Paired with it is an unsigned, decade-old Win32 backdoor carrying an XOR-hidden C2 string and Cloud Hopper-linked YARA hits.
A domain registered in December 2019 and left parked behind ad-network nameservers for more than six years quietly received a new, short-lived TLS certificate on September 1, 2025 — and within weeks was hosting a live-looking command-and-control subdomain. The domain, wthelpdesk.com, is the single richest piece of evidence in this record, and it tells a story less about a specific actor than about how patiently some operators are willing to season their infrastructure before switching it on.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read