C&CMembers
C&C

Shared TLS Certificate Serial Links Three Unrelated Chinese ISPs

Three IP addresses on separate Chinese carriers — China TieTong, China Mobile, and a small Zhejiang provider — all terminate TLS behind a wildcard certificate for *.certfallback.com. Two of them present a byte-identical certificate serial, revealing a centrally provisioned fallback relay layer rather than three independently run hosts.

Aug 17, 2026, 22:47 (UTC+9)Last seenAug 17, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC15MITRE10

Three IP addresses sitting on three separate Chinese internet providers — China TieTong Telecommunications (AS24138), China Mobile (AS56046), and a small Jinhua, Zhejiang Province carrier operating out of AS136190 — all terminate inbound TLS connections behind a certificate issued to a domain that appears nowhere else in this indicator set: a wildcard for *.certfallback.com.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence