C&CMembers
C&C

Fake Baidu, Alibaba TLS Certs Mask Five-Year RAT Campaign

Ten IPs with near-zero AV detections share reused TLS certificates impersonating Baidu, Alibaba, and Tencent/ByteDance CDN domains across unrelated Chinese carriers and a Singapore CDN operator. Alongside them sits a five-year malware lineage disguised as a Synaptics driver, tied by sandbox verdicts to the XRed RAT family.

Aug 2, 2026, 05:41 (UTC+9)Last seenAug 2, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC23MITRE40RegionsTW

Ten IP addresses tied to a single threat-intelligence record show almost no malicious signal on their own — nine come back 0/91 on antivirus scanning, one scrapes a single flag at 1/91. Yet three of those IPs pair up with a twin elsewhere on the internet through an identical TLS certificate, and each pairing wildcards a domain the certificate's real owner has nothing to do with. Two Alibaba Cloud-registered addresses share one GlobalSign-issued certificate for .certfallback.com.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence