
Adware Operator Recycles Qihoo, Alibaba, UnionPay TLS Certs on Carrier IPs
A same-day-registered yunkeit.com subdomain pool feeds config and update material to Ludashi-family PUA binaries signed by two disposable Chinese shell companies. Behind it, China Mobile carrier IPs front the traffic with TLS certificates borrowed from Qihoo 360, Alibaba, and UnionPay International.
Four subdomains under a single Chinese apex — adblock.yunkeit.com, cdn-ali-v3.yunkeit.com, stat.yunkeit.com and upgrade.yunkeit.com — were all registered on the same day, 2025-09-11, through the Hichina registrar (grs-whois.hichina.com, nameservers DNS23/24.HICHINA.COM). Three of the four resolve to the identical A-record, 47.94.14.179, and the fourth, cdn-ali-v3.yunkeit.com, fans out across an eight-address block (180.163.147.83 through .90) behind a CNAME to w.kunluncan.com.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read