
Fake Speed-Test Utility Hides Eight-Year C2 Network With *.malware.com Cert
A shlayer-attributed PUP campaign targeting the energy sector routes traffic through two subdomains of buffernavpose.com, both resolving to a single host presenting a self-signed TLS certificate whose common name is literally '*.malware.com'. The domain has been actively maintained since 2018, with a certificate valid through 2030 and affiliate-parameterised update URLs exposing a structured multi-partner distribution backend.
Two subdomains. One IP address. One self-signed TLS certificate whose common name is literally *.malware.com. The infrastructure behind a shlayer-attributed potentially unwanted program (PUP) campaign targeting the energy sector is not subtle — but its longevity is. The parent domain buffernavpose.com was registered on 2018-05-12 via Dynadot Inc, has been actively maintained through at least April 2026, and carries a certificate valid until 2030-05-11.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read