FILEMembers
FILE

Certificate for signindat.com Labels Itself 'OU=C2' in Plain Text

A self-signed TLS certificate tied to the domain signindat.com carries the organizational-unit field "C2," an unusually blunt slip in infrastructure linked to the doghousepower malware family and the espionage actor Unfading Sea Haze. The domain fronts a lone dropper sample with strong anti-sandbox behavior, leaving most of the campaign's file evidence undocumented.

Jul 18, 2026, 13:56 (UTC+9)Last seenAug 26, 2026Severity77ByCTX TeamActorUnfading Sea HazeIOC12MITRE25RegionsCHJO

Somewhere in the build pipeline behind a single command-and-control domain, an operator generated a self-signed TLS certificate and left its organizational-unit field reading, verbatim, "C2." The domain is signindat.com, resolving to a single address, 193.26.115.45, and the certificate — serial 50fb9fc33758894e18d8b6a0cb42d5044a75078a — carries issuer and subject fields of CN=signindat.com, O=Hermes, OU=C2, with subject alternative names covering both the hostname and its IP.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence