FILEMembers
FILE

Salat Stealer Domains Share TLS Cert Cadence Despite 2-Year Gap

Two Snowglobe-linked C2 domains, sa1atik.cn and websalat.top, registered nearly two years apart, received matching Google Trust Services wildcard certificates within an 18-day window this summer. Analysts say the pattern points to an automated certificate-provisioning workflow rather than any change in the underlying stealer payload.

Aug 19, 2026, 07:10 (UTC+9)Last seenAug 19, 2026Severity77ByCTX TeamActorSnowglobeAnimal FarmIOC7MITRE10RegionsCNDE

The most concrete signal in this update to the Snowglobe-linked campaign isn't a new payload capability — it's a provisioning pattern. Two command-and-control domains, sa1atik.cn and websalat.top, were issued matching Google Trust Services "WE1" wildcard certificates within an 18-day window this summer, despite the domains themselves being registered nearly two years apart.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence