
Fifth IP Joins Huawei-Spoofing Cert Cluster in Guangdong
A new China Telecom address has joined a four-IP cohort sharing one TLS certificate that impersonates Huawei AppGallery and HiCloud, while two unrelated outlier IPs surfaced spoofing Kuaishou- and Tencent-branded CDN identities. The signed 'HappyPicture' adware installer behind the campaign remains unchanged, with zero new hashes this snapshot.
The file side of this campaign has gone quiet — zero new signed installers have surfaced since the last snapshot, while fifteen previously tracked hashes have dropped out of view entirely. But the network layer tells a different story. A newly observed address, 119.147.128.39, has joined a cluster of four IPs already sharing an identical TLS certificate — serial 5ace246430093aa3ef595686 — bringing the cohort to five distinct hosts spread across two /21 netblocks in Guangdong province, all…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read