C&CMembers
C&C

Shared Certificates Tie Decade-Spanning Domains to Proxyware Cluster

Five domains registered between 2013 and 2026 all picked up new TLS certificates from the same two issuers within a seven-week window in mid-2026, while a second trio shares identical 89-day Let's Encrypt validity spans. The pattern points to centrally managed certificate provisioning rather than coincidental renewal by independent site owners.

Sep 10, 2026, 22:28 (UTC+9)Last seenSep 10, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC74MITRE12

Five domains with nothing obviously in common — a fitness-therapy site, a Korean-registered shell, a martial-arts studio, a decade-old Chinese-registered parking page, and a fresh mobile subdomain — picked up new TLS leaf certificates from Google Trust Services within the same seven-week window in mid-2026. tswlmy.com has been registered since April 2013; fxlvpaiguan.com was registered on 2026-07-31, barely a month before the record was compiled.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence