C&CMembers
C&C

Fake Speed-Test Utility Hides Eight-Year C2 Network With *.malware.com Cert

A shlayer-attributed PUP campaign targeting the energy sector routes traffic through two subdomains of buffernavpose.com, both resolving to a single host presenting a self-signed TLS certificate whose common name is literally '*.malware.com'. The domain has been actively maintained since 2018, with a certificate valid through 2030 and affiliate-parameterised update URLs exposing a structured multi-partner distribution backend.

May 28, 2026, 02:13 (UTC+9)Last seenMay 28, 2026Severity100ByCTX TeamIOC14MITRE15

Two subdomains. One IP address. One self-signed TLS certificate whose common name is literally *.malware.com. The infrastructure behind a shlayer-attributed potentially unwanted program (PUP) campaign targeting the energy sector is not subtle — but its longevity is. The parent domain buffernavpose.com was registered on 2018-05-12 via Dynadot Inc, has been actively maintained through at least April 2026, and carries a certificate valid until 2030-05-11.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence