FILEMembers
FILE

Espionage C2 Domain Hides Behind Its Hosting Provider's Certificate

The domain mercadojs.com serves malicious command-and-control traffic from a Hostinger shared-hosting IP whose TLS certificate belongs to Hostinger's own brand, not the attacker. The domain runs its own short-lived Let's Encrypt cert, creating a split identity that lets flagged infrastructure inherit a clean IP reputation.

Sep 3, 2026, 22:54 (UTC+9)Last seenSep 4, 2026Severity100ByCTX TeamActorOperation GhoulIOC4MITRE13RegionsCHJO

An espionage-linked command-and-control domain, mercadojs.com, is presenting a public face that belongs to its landlord rather than its operator. The domain resolves to a single IP address, 82.25.83.117, sitting on AS 47583 — Hostinger International Limited — but the certificate served from that address is issued to "hostinger.com" with a wildcard subject-alternative-name covering *.hosting24.com, both of them Hostinger's own branded properties, not mercadojs.com.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence