C&CMembers
C&C

2345Pinyin Pipeline Grows Fallback Channel as Fuzhou IP Breaks Brand Pattern

Two newly identified C2 IPs extend the 2345Pinyin IME delivery infrastructure across five Chinese carrier networks. A TLS certificate for *.certfallback.com — issued to an Alibaba entity by Belgian CA GlobalSign — stands apart from every other credential in the set, suggesting a deliberate fallback channel outside the primary 2345-branded tier. The pipeline has maintained zero antivirus detection across a seven-year artifact span.

Jun 28, 2026, 10:02 (UTC+9)Last seenJun 28, 2026Severity100ByCTX TeamIOC49MITRE24RegionsCN

Two newly observed IP addresses have extended the confirmed update-and-configuration infrastructure behind the 2345Pinyin input-method editor to five distinct Chinese carrier networks — and one of those IPs presents a TLS certificate that sits entirely outside the established brand ecosystem the pipeline has relied on for years.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence