APTMembers
APT

Fake UnionPay Certificate Ties Together Eighteen IPs on Nine Chinese Carriers

Fifteen of eighteen catalogued IPs across nine Chinese network operators share an identical TLS certificate impersonating *.unionpayintl.com, pointing to one managed CDN edge rather than independent servers. Two file-delivery domains tie that shadow infrastructure directly to Windows binaries signed by four disposable Chinese shell companies.

Jul 10, 2026, 08:36 (UTC+9)Last seenJul 10, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC112MITRE29

Fifteen of eighteen catalogued IP addresses, scattered across nine distinct Chinese network operators, present the exact same TLS certificate serial — b16a258a252d804ceb0eb5ba860f3e5 — for a subject that has nothing to do with any of them: *.unionpayintl.com, issued by DigiCert Basic OV G2 TLS CN RSA4096 SHA256 2022 CA1 and valid from September 30, 2025 to October 31, 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence