FILEMembers
FILE

Fifth IP Joins Huawei-Spoofing Cert Cluster in Guangdong

A new China Telecom address has joined a four-IP cohort sharing one TLS certificate that impersonates Huawei AppGallery and HiCloud, while two unrelated outlier IPs surfaced spoofing Kuaishou- and Tencent-branded CDN identities. The signed 'HappyPicture' adware installer behind the campaign remains unchanged, with zero new hashes this snapshot.

Jul 23, 2026, 13:47 (UTC+9)Last seenJul 23, 2026Severity92ByCTX TeamActorSalty SpiderKuKuIOC18MITRE6

The file side of this campaign has gone quiet — zero new signed installers have surfaced since the last snapshot, while fifteen previously tracked hashes have dropped out of view entirely. But the network layer tells a different story. A newly observed address, 119.147.128.39, has joined a cluster of four IPs already sharing an identical TLS certificate — serial 5ace246430093aa3ef595686 — bringing the cohort to five distinct hosts spread across two /21 netblocks in Guangdong province, all…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence