C&CMembers
C&C

Same Cert Cadence Links Phishing Site to Domain Farm

A phishing-flagged Spanish domain and two nuronapp.com hosts share an identical Let's Encrypt 'YR2' issuer and 89-day validity window issued within days of each other. A wildcard certificate on nuronapp.com further exposes at least nine hidden pivot-brand subdomains never otherwise seen in the record.

Jun 9, 2026, 07:51 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC14MITRE12

Three domains that have nothing else in common — a Spanish site already flagged for phishing, and two hosts sitting under a fifteen-year-old apex — were all issued Let's Encrypt certificates through the identical "YR2" intermediate, with identical 89-day validity windows opened within a nine-day span. lavers.es, which alphaMountain.ai categorizes as Phishing, picked up a YR2 certificate valid 2026-06-05 through 2026-09-03. treddle.nuronapp.com got one valid 2026-05-29 through 2026-08-27.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence