C&CMembers
C&C

Shared TLS Certificate Links Hong Kong IP to Front Domain in C2 Set

A nine-domain, four-IP infrastructure cluster tagged as command-and-control shows one real cross-entity link — an IP and a domain sharing an identical certificate SAN — surrounded by weaker certificate-authority overlaps. The set's lone file is a validly signed Bright Data-branded binary one sandbox flags as the PBot credential stealer.

Sep 13, 2026, 06:52 (UTC+9)Last seenSep 13, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC15MITRE7

Nine domains and four IP addresses tagged as command-and-control infrastructure share almost nothing in common — different registrars, different countries, different certificate authorities — except for one pairing that stands out precisely because it shouldn't exist by coincidence. The IP address 45.154.14.190, registered to MOACK.Co.LTD under AS 138195 in Hong Kong, presents a TLS certificate whose subject and subject-alternative-name field read "anfangshen.com" and "*.anfangshen.com." The…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence