APTMembers
APT

Dormant Domain Reactivated With Fresh Cert to Power Backdoor C2

A domain registered in 2019 and parked for six years suddenly received a new 89-day Let's Encrypt certificate in September 2025, then began hosting randomized check-in paths under a live-looking subdomain. Paired with it is an unsigned, decade-old Win32 backdoor carrying an XOR-hidden C2 string and Cloud Hopper-linked YARA hits.

Jun 14, 2026, 02:27 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamActorRed ApolloPotassiumIOC7RegionsDE

A domain registered in December 2019 and left parked behind ad-network nameservers for more than six years quietly received a new, short-lived TLS certificate on September 1, 2025 — and within weeks was hosting a live-looking command-and-control subdomain. The domain, wthelpdesk.com, is the single richest piece of evidence in this record, and it tells a story less about a specific actor than about how patiently some operators are willing to season their infrastructure before switching it on.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence