
Expired C2 Domain Closes Loop on Red Apollo KMSPico Adware Campaign
A single short-lived domain registered in October 2017 and abandoned within a year has been confirmed as the network checkin endpoint for two NSIS-packaged OutBrowse installers masquerading as the KMSPico Windows activation crack. The finding closes the delivery-to-C2 loop on a campaign attributed to Red Apollo and targeting German manufacturing. A two-year gap between the 2015 payload files and the 2017 domain registration points to deliberate infrastructure rotation paired with durable, sandbox-aware tooling.
A single domain registered in October 2017 — idyllicdownload.com, acquired through Silver Domain Names LLC and abandoned within a year — has emerged as the confirmed network checkin endpoint for a pair of NSIS-packaged OutBrowse adware installers that masquerade as the KMSPico Windows activation crack. The domain's addition to the indicator catalog closes the delivery-to-C2 loop on a campaign attributed to Red Apollo, the China-aligned threat actor also tracked under the aliases APT10,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read