C&CMembers
C&C

CDN-Masquerade TLS Cluster and First C2 Domain Expand PubNubRAT Campaign

Thirteen Chinese IPs sharing a single Sectigo wildcard certificate for *.bytecdn.cn form a reverse-proxy layer hiding C2 traffic behind a major CDN brand's TLS identity. The first confirmed C2 domain, intf-pc.whnuowo.cn, exposes encrypted configuration endpoints, while a parallel seven-IP cluster presents UnionPay OV certificates — together revealing a structured, multi-tier network fabric beneath a campaign previously known only for its payloads.

Jun 7, 2026, 07:53 (UTC+9)Last seenJun 7, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC153MITRE10

Thirteen IP addresses spanning six Chinese autonomous systems — China Unicom, China Telecom, China Mobile, and Jinhua Weian InfoTech among them — have been found presenting an identical Sectigo DV wildcard certificate for *.bytecdn.cn (serial 152bfd07c372d944c3ac6feff2e606bd), forming a geographically distributed reverse-proxy layer that cloaks command-and-control traffic behind the TLS identity of one of China's largest consumer internet CDN brands.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence