
VPN Trojan Cluster Adds 10 IPs, 6 Domains, No New Malware
A signed VPN/proxy-trojan operation shows zero new malicious binaries this pass, but its network layer keeps expanding. A single TLS certificate serial for *.certfallback.com now spans four hosts across three unrelated carriers in China and the Philippines.
The latest pass through this VPN-and-proxy-trojan operation surfaces ten additional IP addresses and six additional domains — and not a single new malicious binary. That lopsided delta is itself the story. While the signed installers that anchor this campaign have sat unchanged for months, the network layer underneath them keeps expanding, and the clearest evidence of that expansion is a single TLS certificate serial, 363a6b88ee219be351b40934, now confirmed live on four separate hosts spread…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read