
Salty Spider Expands to Dual-Domain C2 With UnionPay TLS Fingerprint
Nine new C2 domains, 31 IP addresses, and a second DigiCert code-signing certificate expose the full redundant infrastructure behind the Salty Spider adware campaign. Seventeen Chinese IPs across unrelated autonomous systems present *.unionpayintl.com TLS certificates, linking payload delivery to financial-sector network infrastructure and complicating network-layer blocking.
Nine command-and-control domains, nine documented URL paths, and 31 IP addresses — none present in prior coverage — have surfaced in the latest observed activity tied to the Salty Spider campaign, exposing for the first time the full operational infrastructure behind a signed-binary adware toolkit that CTX Team has been tracking across multiple observation windows.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read