
Fake UnionPay TLS Certificate Ties Together 19 Chinese Adware Hosts
Nineteen IP addresses spanning five-plus Chinese ISPs all serve an identical wildcard certificate impersonating UnionPay International, fronting Ludashi/Chinad/PolarWind adware installers. The certificate discipline — renewed across a full cycle rather than replaced — reveals an operator prioritizing identity persistence over disposable infrastructure.
Nineteen IP addresses scattered across five or more distinct Chinese ISPs — China Unicom's China169 backbone, three separate China Mobile autonomous systems, and a scatter of regional China Telecom blocks — all present the identical TLS certificate when a browser connects to them. The subject line reads *.unionpayintl.com, organisation "UnionPay International Co., Ltd.," issued by DigiCert's Basic OV G2 TLS CA.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read