
Fake Baidu, Alibaba TLS Certs Mask Five-Year RAT Campaign
Ten IPs with near-zero AV detections share reused TLS certificates impersonating Baidu, Alibaba, and Tencent/ByteDance CDN domains across unrelated Chinese carriers and a Singapore CDN operator. Alongside them sits a five-year malware lineage disguised as a Synaptics driver, tied by sandbox verdicts to the XRed RAT family.
Ten IP addresses tied to a single threat-intelligence record show almost no malicious signal on their own — nine come back 0/91 on antivirus scanning, one scrapes a single flag at 1/91. Yet three of those IPs pair up with a twin elsewhere on the internet through an identical TLS certificate, and each pairing wildcards a domain the certificate's real owner has nothing to do with. Two Alibaba Cloud-registered addresses share one GlobalSign-issued certificate for .certfallback.com.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read