C&CMembers
C&C

Salty Spider Adds Second CDN Channel to Trojanized 2345PCSafe Delivery

A second CDN-fronted update endpoint, dl-up.2345cdn.com, is now confirmed active alongside the previously documented download.2345cdn.com, expanding the delivery infrastructure behind the trojanized 2345PCSafe security suite. The dual-CDN architecture spans both ChinaNetCenter and Alibaba Kunlun CDN, adding 23 new IP addresses and deliberate redundancy to a campaign whose signed payload set remains valid through July 2026.

Jun 6, 2026, 15:47 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC88MITRE2

Since CTX Team's earlier coverage of this campaign, the delivery infrastructure backing the trojanized 2345PCSafe (2345安全卫士) security suite has grown in a specific and operationally significant direction: a second CDN-fronted update endpoint, dl-up.2345cdn.com, is now confirmed active alongside the previously documented download.2345cdn.com, and 23 additional IP addresses have been mapped to the anycast pools behind both domains.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence