
2345Pinyin Pipeline Grows Fallback Channel as Fuzhou IP Breaks Brand Pattern
Two newly identified C2 IPs extend the 2345Pinyin IME delivery infrastructure across five Chinese carrier networks. A TLS certificate for *.certfallback.com — issued to an Alibaba entity by Belgian CA GlobalSign — stands apart from every other credential in the set, suggesting a deliberate fallback channel outside the primary 2345-branded tier. The pipeline has maintained zero antivirus detection across a seven-year artifact span.
Two newly observed IP addresses have extended the confirmed update-and-configuration infrastructure behind the 2345Pinyin input-method editor to five distinct Chinese carrier networks — and one of those IPs presents a TLS certificate that sits entirely outside the established brand ecosystem the pipeline has relied on for years.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read