
18 C2 Nodes Hide Behind Alibaba, Baidu, and 2345.com TLS Certs
A severity-100 campaign has built an 18-node command-and-control network whose TLS certificates impersonate four major Chinese CDN platforms, making malicious traffic structurally indistinguishable from routine HTTPS connections. The operator spread nodes across five autonomous systems — including China Unicom, China Telecom, and Alibaba Cloud backbones — to defeat both certificate-based and ASN-based blocking. A zero-detection Chrome extension payload has evaded 76 antivirus engines across five months of active circulation.
Eighteen IP addresses flagged as command-and-control servers share an architectural feature that sets this campaign apart from conventional attacker-controlled hosting: every node in the set presents a TLS certificate belonging to a major Chinese internet platform — Alibaba CDN, Baidu, 2345.com, or Baidu DNS — making outbound C2 traffic structurally indistinguishable from routine HTTPS connections to some of China's highest-volume services.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read