
Salat Stealer Domains Share TLS Cert Cadence Despite 2-Year Gap
Two Snowglobe-linked C2 domains, sa1atik.cn and websalat.top, registered nearly two years apart, received matching Google Trust Services wildcard certificates within an 18-day window this summer. Analysts say the pattern points to an automated certificate-provisioning workflow rather than any change in the underlying stealer payload.
The most concrete signal in this update to the Snowglobe-linked campaign isn't a new payload capability — it's a provisioning pattern. Two command-and-control domains, sa1atik.cn and websalat.top, were issued matching Google Trust Services "WE1" wildcard certificates within an 18-day window this summer, despite the domains themselves being registered nearly two years apart.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read