C&CMembers
C&C

13-Node C2 Pool Borrows UnionPay Wildcard TLS to Mask Ludashi Adware

Thirteen China-geolocated IPs across five autonomous systems are presenting a genuine DigiCert-issued wildcard TLS certificate belonging to UnionPay International as their HTTPS identity. A newly identified delivery domain, cdn-file.szyrtech.com, shares an IP with the C2 pool, closing the gap between file distribution and callback infrastructure for the first time in this campaign's documented history.

Jun 2, 2026, 08:17 (UTC+9)Last seenJun 2, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC73MITRE3

Thirteen China-geolocated IP addresses, distributed across five distinct autonomous systems, are presenting a wildcard TLS certificate belonging to UnionPay International Co., Ltd. as their HTTPS identity — a trust-borrowing technique that gives campaign traffic the appearance of legitimate Chinese financial-sector communications.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence