
Chinese Adware Ring Reuses Certs to Spoof UnionPay and Huawei
A cluster of command infrastructure on China Unicom's AS4837 backbone serves two duplicated TLS certificates impersonating UnionPay International and Huawei's AppGallery/CDN. The same operational discipline shows up in a code-signing certificate reused across six adware payloads for roughly thirteen months.
Every piece of command infrastructure in this record — all seven IP addresses tied to the cluster — sits on a single Chinese carrier backbone, AS4837, CHINA UNICOM China169 Backbone. That alone would be a footnote for China-facing infrastructure. What makes it a story is what those IPs present to anyone who connects to them: two separate, duplicated TLS certificates, each spoofing a different trusted brand.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read