C&CMembers
C&C

Matching 89-Day Certificates Link Two 'Unrelated' Crack Sites

A game-mod lure and a fake Adobe-crack domain issue TLS certificates on an identical 89-day rhythm, and the delivery IP's own certificate points back to the domain's nameserver namespace. Behind that shared provisioning pattern sits a commodity bundle of LummaStealer, a disguised XMRig miner, and an AsyncRAT-tagged loader.

Jul 26, 2026, 13:43 (UTC+9)Last seenJul 26, 2026Severity100ByCTX TeamIOC28MITRE32RegionsCN

Two lure domains that look, on the surface, like they belong to entirely different corners of the pirated-software economy — a game-mod hub called modedapk.net and an Adobe-crack site called adobephotoshopcrack.com — are provisioning their TLS certificates on an identical clock. modedapk.net's certificate, issued by Let's Encrypt under issuer YE1, runs from 2026-07-12 to 2026-10-10. adobephotoshopcrack.com's certificate, issued under YR1, runs from 2026-06-11 to 2026-09-09.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence