C&CMembers
C&C

Four Signed Certs, Ten IPs, One UnionPay Disguise: IcedID's Dual-Layer Evasion

Seventeen Windows executables signed by four Chinese legal entities beacon to a C2 backend whose ten IPs all present a wildcard TLS certificate issued to UnionPay International, making malicious HTTPS traffic resemble legitimate payment-network communications. CTX Team has tracked the build pipeline from October 2024 through at least May 2026, with active certificate renewals sustaining trusted signing status throughout.

May 26, 2026, 17:06 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamIOC39MITRE46

Seventeen Windows executables and DLLs, all validly signed by DigiCert's Trusted G4 Code Signing chain, are circulating as system-cleaning and security utilities — and every one of them beacons to a C2 backend whose ten IP addresses present a wildcard TLS certificate issued to UnionPay International Co., Ltd. The combination is not accidental.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence