APTMembers
APT

Fifteen New Addresses Cluster Inside One China Mobile ASN

A fresh batch of 17 IP indicators tied to a signed-adware campaign shows 15 of them resolving inside a single China Mobile autonomous system, AS9808. Each address answers HTTPS traffic with wildcard TLS certificates spoofing major Chinese consumer brands, pointing to carrier-grade CDN space rather than dedicated attacker infrastructure.

Jun 1, 2026, 17:20 (UTC+9)Last seenJul 2, 2026Severity77ByCTX TeamActorSalty SpiderKuKuIOC122MITRE17

Seventeen IP indicators sit in this record, and fourteen of them are new to this pass. Almost all of them — fifteen of the seventeen — resolve inside a single autonomous system: AS9808, registered to China Mobile Communications Group Co., Ltd. That concentration is the most consequential fact in this update, eclipsing the signed-binary story that anchored earlier coverage of this cluster.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence