
Fake UnionPay Certificate Ties Together Eighteen IPs on Nine Chinese Carriers
Fifteen of eighteen catalogued IPs across nine Chinese network operators share an identical TLS certificate impersonating *.unionpayintl.com, pointing to one managed CDN edge rather than independent servers. Two file-delivery domains tie that shadow infrastructure directly to Windows binaries signed by four disposable Chinese shell companies.
Fifteen of eighteen catalogued IP addresses, scattered across nine distinct Chinese network operators, present the exact same TLS certificate serial — b16a258a252d804ceb0eb5ba860f3e5 — for a subject that has nothing to do with any of them: *.unionpayintl.com, issued by DigiCert Basic OV G2 TLS CN RSA4096 SHA256 2022 CA1 and valid from September 30, 2025 to October 31, 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read