
Chinese Adware Chain Hides RAT Behind UnionPay-Spoofing TLS Certs
A LuDaShi/PolarWind-style installer chain rides China Unicom's AS4837 backbone behind TLS certificates impersonating UnionPay International and a generic 'certfallback' brand. Inside one of two shared code-signing cohorts, three files trip a sandbox-named 'PubNubRAT' verdict, raising the stakes of trusting the certificate wholesale.
Ten of eleven IP addresses tied to a Chinese adware delivery cluster CTX Team has been mapping sit inside a single autonomous system — AS4837, CHINA UNICOM China169 Backbone — and seven of those ten present an identical .unionpayintl.com wildcard TLS certificate that has nothing to do with UnionPay International's actual payment infrastructure.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read