APTMembers
APT

Decade-Old German Domains Reactivated as Emotet C2 Backbone Targeting Philippines

Four C2 domains registered through a single German registrar between 2005 and 2012 were quietly reactivated with fresh TLS certificates across a five-month window in 2025, then activated as Emotet command-and-control nodes against Philippine targets in early 2026. A sixth domain, registered one day before the campaign went live, carries a TLS certificate predating its own creation by roughly 100 days — pointing to deliberate certificate pre-staging. Together the two infrastructure tiers reveal an operator managing a long-horizon asset portfolio with a level of discipline uncommon in commodity malware campaigns.

Jun 28, 2026, 16:53 (UTC+9)Last seenJun 28, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC21RegionsPH

Six command-and-control domains now active in an Emotet campaign targeting the Philippines share a striking infrastructure characteristic: four of them were registered between 2005 and 2012 through a single German registrar, Cronon GmbH, and have been sitting dormant — or at least benign-facing — for years, accumulating the kind of domain-age legitimacy that reputation-based defences routinely reward with a pass.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence