
Cloned UnionPay TLS Certificate Links 12 Chinese Carrier IPs
A single spoofed '*.unionpayintl.com' certificate serial appears identically across a dozen unrelated China Mobile, Unicom and Telecom IP ranges, fronting infrastructure for a family of signed adware installers. The pattern points to a commodity PUP operation with unusually disciplined certificate rotation, not the FIN6 or APT28 activity the feed tags suggest.
A single TLS certificate serial, b16a258a252d804ceb0eb5ba860f3e5, presents identically across 12 IP addresses that have no obvious business relationship — spanning China Mobile (AS56045, AS56046, AS9808), China Unicom (AS4837), multiple China Telecom provincial networks (AS142404, AS134762, AS141998, AS138169) and CT-HangZhou-IDC (AS58461).
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read