
APT15-Linked Set Shows Three-Tier, Cert-Rotated Hosting Discipline
A ten-domain, three-IP infrastructure package tied to the APT15/Ke3chang ecosystem reveals a deliberately segmented hosting model rather than a single point of failure. Four subdomains masquerade inside a real Thai medical-software vendor's DNS zone on a shared IP, a separate domain fronts a nine-domain wildcard certificate, and three unrelated IPs sit isolated on three different continents.
Four subdomains — meddup.bmscloud.in.th, api.notify.bmscloud.in.th, donorcheck.bmscloud.in.th, and moph-phr.bmscloud.in.th — all live inside the same legitimate-looking DNS zone, bmscloud.in.th, registered through the Thai registrar THNIC to Bangkok Medical Software Co., Ltd. Three of the four resolve to the identical IP, 171.103.78.30, and the cohort as a whole shares one registrar across all four names — the kind of single-administrative-point pattern that tells an analyst these are…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read