
Salty Spider Adds Second CDN Channel to Trojanized 2345PCSafe Delivery
A second CDN-fronted update endpoint, dl-up.2345cdn.com, is now confirmed active alongside the previously documented download.2345cdn.com, expanding the delivery infrastructure behind the trojanized 2345PCSafe security suite. The dual-CDN architecture spans both ChinaNetCenter and Alibaba Kunlun CDN, adding 23 new IP addresses and deliberate redundancy to a campaign whose signed payload set remains valid through July 2026.
Since CTX Team's earlier coverage of this campaign, the delivery infrastructure backing the trojanized 2345PCSafe (2345安全卫士) security suite has grown in a specific and operationally significant direction: a second CDN-fronted update endpoint, dl-up.2345cdn.com, is now confirmed active alongside the previously documented download.2345cdn.com, and 23 additional IP addresses have been mapped to the anycast pools behind both domains.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read