C&CMembers
C&C

Adware Operator Recycles Qihoo, Alibaba, UnionPay TLS Certs on Carrier IPs

A same-day-registered yunkeit.com subdomain pool feeds config and update material to Ludashi-family PUA binaries signed by two disposable Chinese shell companies. Behind it, China Mobile carrier IPs front the traffic with TLS certificates borrowed from Qihoo 360, Alibaba, and UnionPay International.

Sep 20, 2026, 06:37 (UTC+9)Last seenSep 20, 2026Severity100ByCTX TeamIOC26MITRE36

Four subdomains under a single Chinese apex — adblock.yunkeit.com, cdn-ali-v3.yunkeit.com, stat.yunkeit.com and upgrade.yunkeit.com — were all registered on the same day, 2025-09-11, through the Hichina registrar (grs-whois.hichina.com, nameservers DNS23/24.HICHINA.COM). Three of the four resolve to the identical A-record, 47.94.14.179, and the fourth, cdn-ali-v3.yunkeit.com, fans out across an eight-address block (180.163.147.83 through .90) behind a CNAME to w.kunluncan.com.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence