APTMembers
APT

Six-Year-Old Domain, Faked Autodiscover Cert Outshine Blank File Hashes

Three Thai subdomains carved from a real medical-software vendor's namespace, a Singapore IP wearing a forged A2 Hosting certificate, and a six-year-old Chinese domain freshly reissued form the only legible signal in a record with 16 file indicators and zero file-level metadata. CTX Team reads this as a hosting-and-camouflage fingerprint, not a payload story.

Jul 15, 2026, 13:37 (UTC+9)Last seenJul 15, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC23MITRE29

Three subdomains carved out of a Thai medical-software vendor's own domain zone, a Singapore-hosted IP wearing a certificate that borrows another hosting provider's name, and a six-year-old Chinese-registered domain freshly reissued with a GoDaddy certificate — together these form the only legible signal in a record that otherwise offers almost nothing.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence