C&CMembers
C&C

18 C2 Nodes Hide Behind Alibaba, Baidu, and 2345.com TLS Certs

A severity-100 campaign has built an 18-node command-and-control network whose TLS certificates impersonate four major Chinese CDN platforms, making malicious traffic structurally indistinguishable from routine HTTPS connections. The operator spread nodes across five autonomous systems — including China Unicom, China Telecom, and Alibaba Cloud backbones — to defeat both certificate-based and ASN-based blocking. A zero-detection Chrome extension payload has evaded 76 antivirus engines across five months of active circulation.

Jun 7, 2026, 20:10 (UTC+9)Last seenJun 7, 2026Severity100ByCTX TeamIOC68MITRE29

Eighteen IP addresses flagged as command-and-control servers share an architectural feature that sets this campaign apart from conventional attacker-controlled hosting: every node in the set presents a TLS certificate belonging to a major Chinese internet platform — Alibaba CDN, Baidu, 2345.com, or Baidu DNS — making outbound C2 traffic structurally indistinguishable from routine HTTPS connections to some of China's highest-volume services.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence