C&CMembers
C&C

One Wildcard Certificate Ties APT28 Infrastructure Across Six Nations

Eighteen IP addresses spanning the US, Hong Kong, Vietnam, South Korea, Malaysia and Thailand all present the identical certfallback.com TLS certificate. The shared certificate — rather than any malicious file — is what binds this fallback beaconing layer into a single traceable operator footprint.

Sep 24, 2026, 14:37 (UTC+9)Last seenSep 24, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC30MITRE2

Eighteen IP addresses scattered across the United States, Hong Kong, Vietnam, South Korea, Malaysia and Thailand are all presenting the identical TLS certificate — a wildcard issued for a domain whose name gives away its purpose: certfallback.com. The certificate carries serial number 6696262f452fcf46b79266a8, was issued by GlobalSign GCC R46 OV TLS CA 2025 to an organization listed as Alibaba (China) Technology Co., Ltd. in Hangzhou, Zhejiang, and runs from 2026-07-30 through 2027-02-14.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence