C&CMembers
C&C

Signed-Adware Campaign Adds PubNubRAT and New C2 Backend

A campaign distributing validly-signed PC utilities across Chinese-market endpoints has expanded its infrastructure with a new function-partitioned C2 domain cluster and eight CDN-layer IPs, while sandbox analysis has confirmed PubNubRAT inside two DigiCert-signed DLLs. The RAT routes its command channel through PubNub's cloud messaging service, rendering it invisible to network-layer detection.

Jun 5, 2026, 08:24 (UTC+9)Last seenJun 5, 2026Severity100ByCTX TeamIOC46MITRE23

Since CTX Team's earlier coverage of this campaign's UnionPay-fingerprinted TLS infrastructure, the operation has expanded in two structurally significant directions: a wholly new, function-partitioned command-and-control backend has been provisioned under the domain tjbxldkj.cn, and eight fresh IP addresses bound by a shared Sectigo wildcard certificate have joined the delivery layer — all absent from the prior reporting.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence