FILEMembers
FILE

One Domain, a Disposable Cert, and an APT29 Label That Doesn't Fit

A threat-feed entry ties holzbrenzii.com — a year-old domain with a short-lived wildcard TLS certificate — to APT29 and Remcos malware, but the attribution has no verifiable link to the domain's evidence. Four vendors flag the site as phishing/fraud infrastructure; everything beyond that is unpopulated metadata riding along for the label.

Jul 24, 2026, 21:34 (UTC+9)Last seenJul 24, 2026Severity83ByCTX TeamActorAPT29MinidionisIOC2MITRE28RegionsAUBABGECHR

A domain called holzbrenzii.com went live on 2025-06-23 through registrar PDR Ltd. d/b/a PublicDomainRegistry.com, sat quietly on a single hosting record for over a year, then picked up a wildcard TLS certificate with an unusually tight 89-day validity window. That's the entirety of the corroborated evidence in a threat-feed entry that also carries an APT29 attribution and a Remcos malware tag — labels that, on closer inspection, are bolted onto a record with no file, no payload, and no…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence