C&CMembers
C&C

One Wildcard Certificate Links Five China Unicom IPs Across Four Subnets

Five IP addresses spread across four separate CIDR blocks inside China Unicom's backbone all serve the identical *.certfallback.com wildcard certificate, a pattern CTX Team reads as a deliberately engineered fallback pool rather than shared hosting. All five addresses show zero VirusTotal detections, making the cluster invisible to reputation-based defenses.

Aug 30, 2026, 14:45 (UTC+9)Last seenAug 30, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC12MITRE16

Five IP addresses sitting on four separate subnets inside China Unicom's core network all answer HTTPS requests with the exact same TLS certificate — serial 6696262f452fcf46b79266a8, issued by GlobalSign GCC R46 OV TLS CA 2025, carrying the subject organisation "Alibaba (China) Technology Co., Ltd." and a wildcard subject name of *.certfallback.com. That is not a coincidence of shared hosting; it is one certificate identity deliberately deployed across a diversified physical footprint.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence