C&CMembers
C&C

Seven Alibaba IPs in Four Countries Share One TLS Certificate

A fresh sweep of a proxyware-and-VPN-trojan campaign adds 27 domains and 12 IPs, revealing a hidden hosting layer rather than new malware. Seven IPs spread across the US, Singapore, the Philippines and Hong Kong all answer with the identical *.certfallback.com certificate on Alibaba Cloud's AS24429, while two Let's Encrypt cohorts quietly bind together otherwise-unrelated domains.

Aug 17, 2026, 14:31 (UTC+9)Last seenAug 17, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC177MITRE21

Seven IP addresses split across the United States, Singapore, the Philippines and Hong Kong now answer HTTPS probes with the identical TLS certificate — a wildcard for *.certfallback.com, serial 6696262f452fcf46b79266a8, issued by GlobalSign GCC R46 OV TLS CA 2025 and valid from July 30, 2026 through February 14, 2027. That is the strongest new signal in a fresh sweep of an already-tracked proxyware-and-VPN-trojan campaign, one that in this pass added 27 domains and 12 IP addresses to the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence