
Matching 89-Day Certificates Link Two 'Unrelated' Crack Sites
A game-mod lure and a fake Adobe-crack domain issue TLS certificates on an identical 89-day rhythm, and the delivery IP's own certificate points back to the domain's nameserver namespace. Behind that shared provisioning pattern sits a commodity bundle of LummaStealer, a disguised XMRig miner, and an AsyncRAT-tagged loader.
Two lure domains that look, on the surface, like they belong to entirely different corners of the pirated-software economy — a game-mod hub called modedapk.net and an Adobe-crack site called adobephotoshopcrack.com — are provisioning their TLS certificates on an identical clock. modedapk.net's certificate, issued by Let's Encrypt under issuer YE1, runs from 2026-07-12 to 2026-10-10. adobephotoshopcrack.com's certificate, issued under YR1, runs from 2026-06-11 to 2026-09-09.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read