
Signed-Adware Campaign Adds PubNubRAT and New C2 Backend
A campaign distributing validly-signed PC utilities across Chinese-market endpoints has expanded its infrastructure with a new function-partitioned C2 domain cluster and eight CDN-layer IPs, while sandbox analysis has confirmed PubNubRAT inside two DigiCert-signed DLLs. The RAT routes its command channel through PubNub's cloud messaging service, rendering it invisible to network-layer detection.
Since CTX Team's earlier coverage of this campaign's UnionPay-fingerprinted TLS infrastructure, the operation has expanded in two structurally significant directions: a wholly new, function-partitioned command-and-control backend has been provisioned under the domain tjbxldkj.cn, and eight fresh IP addresses bound by a shared Sectigo wildcard certificate have joined the delivery layer — all absent from the prior reporting.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read