APTMembers
APT

Expired C2 Domain Closes Loop on Red Apollo KMSPico Adware Campaign

A single short-lived domain registered in October 2017 and abandoned within a year has been confirmed as the network checkin endpoint for two NSIS-packaged OutBrowse installers masquerading as the KMSPico Windows activation crack. The finding closes the delivery-to-C2 loop on a campaign attributed to Red Apollo and targeting German manufacturing. A two-year gap between the 2015 payload files and the 2017 domain registration points to deliberate infrastructure rotation paired with durable, sandbox-aware tooling.

Jun 6, 2026, 03:06 (UTC+9)Last seenJun 13, 2026Severity72ByCTX TeamActorRed ApolloPotassiumIOC9MITRE38RegionsDE

A single domain registered in October 2017 — idyllicdownload.com, acquired through Silver Domain Names LLC and abandoned within a year — has emerged as the confirmed network checkin endpoint for a pair of NSIS-packaged OutBrowse adware installers that masquerade as the KMSPico Windows activation crack. The domain's addition to the indicator catalog closes the delivery-to-C2 loop on a campaign attributed to Red Apollo, the China-aligned threat actor also tracked under the aliases APT10,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence