
Four Signed Certs, Ten IPs, One UnionPay Disguise: IcedID's Dual-Layer Evasion
Seventeen Windows executables signed by four Chinese legal entities beacon to a C2 backend whose ten IPs all present a wildcard TLS certificate issued to UnionPay International, making malicious HTTPS traffic resemble legitimate payment-network communications. CTX Team has tracked the build pipeline from October 2024 through at least May 2026, with active certificate renewals sustaining trusted signing status throughout.
Seventeen Windows executables and DLLs, all validly signed by DigiCert's Trusted G4 Code Signing chain, are circulating as system-cleaning and security utilities — and every one of them beacons to a C2 backend whose ten IP addresses present a wildcard TLS certificate issued to UnionPay International Co., Ltd. The combination is not accidental.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read