
Seven Alibaba IPs in Four Countries Share One TLS Certificate
A fresh sweep of a proxyware-and-VPN-trojan campaign adds 27 domains and 12 IPs, revealing a hidden hosting layer rather than new malware. Seven IPs spread across the US, Singapore, the Philippines and Hong Kong all answer with the identical *.certfallback.com certificate on Alibaba Cloud's AS24429, while two Let's Encrypt cohorts quietly bind together otherwise-unrelated domains.
Seven IP addresses split across the United States, Singapore, the Philippines and Hong Kong now answer HTTPS probes with the identical TLS certificate — a wildcard for *.certfallback.com, serial 6696262f452fcf46b79266a8, issued by GlobalSign GCC R46 OV TLS CA 2025 and valid from July 30, 2026 through February 14, 2027. That is the strongest new signal in a fresh sweep of an already-tracked proxyware-and-VPN-trojan campaign, one that in this pass added 27 domains and 12 IP addresses to the…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read