APTMembers
APT

Shared Self-Signed TLS Cert Links Bytedance, Zenlayer IPs to VPN Trojans

One decade-valid self-signed certificate turns up unmodified on two IPs in Bytedance's US block and two in Zenlayer's Philippines block, tying the pair of unrelated clouds into a single C2-shaped asset. Behind that infrastructure sits a WEILAI-signed WireVPN loader/DLL kept alive months after its certificate was revoked, a VPNMaster PUA, and a Bright Data-branded binary a sandbox confirms as a PBot stealer.

Aug 16, 2026, 22:28 (UTC+9)Last seenAug 16, 2026Severity100ByCTX TeamActorUAC-0063TAG-110IOC41MITRE21

Four IP addresses that share nothing else in common are running the identical self-signed TLS certificate — two sitting inside Bytedance's US-registered network block, two inside Zenlayer's Philippines allocation on the other side of the Pacific. The certificate carries serial number 1acf3e37b37910d932ea64e6bb27615d6484c07d, with both issuer and subject fields recorded simply as "NONE," and it is valid from March 12, 2024 clear through March 10, 2034 — a ten-year span that is itself unusual for…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence