APTMembers
APT

One Blank TLS Certificate Links Four Unrelated Cloud Networks

Thirteen IP addresses across a hyperscale social-media company's own network, a budget VPS reseller, and two obscure Russian hosts all present the identical self-signed 'NONE/NONE' certificate. The overlap ties otherwise unrelated infrastructure to signed VPN-branded trojans distributed under names like WireVPN and VPNMaster.

Sep 17, 2026, 06:29 (UTC+9)Last seenSep 17, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC96MITRE22

Thirteen IP addresses spread across a hyperscale social-media company's own network, a discount VPS reseller with points of presence on four continents, and two little-known hosting shells registered in Russia all present the exact same self-signed TLS certificate — serial 1acf3e37b37910d932ea64e6bb27615d6484c07d, with both its issuer and subject fields rendered as the literal string "NONE." That certificate, valid from March 2024 through March 2034, is not the kind of artefact that shows up…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence