
CDN-Masquerade TLS Cluster and First C2 Domain Expand PubNubRAT Campaign
Thirteen Chinese IPs sharing a single Sectigo wildcard certificate for *.bytecdn.cn form a reverse-proxy layer hiding C2 traffic behind a major CDN brand's TLS identity. The first confirmed C2 domain, intf-pc.whnuowo.cn, exposes encrypted configuration endpoints, while a parallel seven-IP cluster presents UnionPay OV certificates — together revealing a structured, multi-tier network fabric beneath a campaign previously known only for its payloads.
Thirteen IP addresses spanning six Chinese autonomous systems — China Unicom, China Telecom, China Mobile, and Jinhua Weian InfoTech among them — have been found presenting an identical Sectigo DV wildcard certificate for *.bytecdn.cn (serial 152bfd07c372d944c3ac6feff2e606bd), forming a geographically distributed reverse-proxy layer that cloaks command-and-control traffic behind the TLS identity of one of China's largest consumer internet CDN brands.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read