APTMembers
APT

Chinese Adware Chain Hides RAT Behind UnionPay-Spoofing TLS Certs

A LuDaShi/PolarWind-style installer chain rides China Unicom's AS4837 backbone behind TLS certificates impersonating UnionPay International and a generic 'certfallback' brand. Inside one of two shared code-signing cohorts, three files trip a sandbox-named 'PubNubRAT' verdict, raising the stakes of trusting the certificate wholesale.

Aug 15, 2026, 22:30 (UTC+9)Last seenAug 15, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC59MITRE14

Ten of eleven IP addresses tied to a Chinese adware delivery cluster CTX Team has been mapping sit inside a single autonomous system — AS4837, CHINA UNICOM China169 Backbone — and seven of those ten present an identical .unionpayintl.com wildcard TLS certificate that has nothing to do with UnionPay International's actual payment infrastructure.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence