C&CMembers
C&C

Salty Spider Expands to Dual-Domain C2 With UnionPay TLS Fingerprint

Nine new C2 domains, 31 IP addresses, and a second DigiCert code-signing certificate expose the full redundant infrastructure behind the Salty Spider adware campaign. Seventeen Chinese IPs across unrelated autonomous systems present *.unionpayintl.com TLS certificates, linking payload delivery to financial-sector network infrastructure and complicating network-layer blocking.

May 27, 2026, 17:56 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC100MITRE8

Nine command-and-control domains, nine documented URL paths, and 31 IP addresses — none present in prior coverage — have surfaced in the latest observed activity tied to the Salty Spider campaign, exposing for the first time the full operational infrastructure behind a signed-binary adware toolkit that CTX Team has been tracking across multiple observation windows.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence