
Fleet of Look-Alike Domains Shares One WE1 Certificate Pipeline
Five domains issued certificates by the same Google Trust Services 'WE1' intermediate within a one-month window are delivering a KMSpico-crack downloader, a Kaspersky-spoofing stealer, and a TiWorker-impersonating clipper. Shared Namecheap registration and Cloudflare nameservers point to a single operator running scripted, disposable infrastructure rather than isolated drops.
Five domains in a seven-domain delivery fleet — cartmask.xyz, fluxautomation.cc, microlsireqjn.com, rabbitsbird.info and silversongs.info — were issued certificates by the same Google Trust Services intermediate, "WE1," inside a roughly one-month window running from June 6 to July 7, 2026. That kind of certificate-issuance cadence, layered on top of a shared Namecheap registration workflow across three of those domains, is the signature of tooling, not coincidence — an operator standing up…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read