
13-Node C2 Pool Borrows UnionPay Wildcard TLS to Mask Ludashi Adware
Thirteen China-geolocated IPs across five autonomous systems are presenting a genuine DigiCert-issued wildcard TLS certificate belonging to UnionPay International as their HTTPS identity. A newly identified delivery domain, cdn-file.szyrtech.com, shares an IP with the C2 pool, closing the gap between file distribution and callback infrastructure for the first time in this campaign's documented history.
Thirteen China-geolocated IP addresses, distributed across five distinct autonomous systems, are presenting a wildcard TLS certificate belonging to UnionPay International Co., Ltd. as their HTTPS identity — a trust-borrowing technique that gives campaign traffic the appearance of legitimate Chinese financial-sector communications.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read