APTMembers
APT

VPN Trojan Cluster Adds 10 IPs, 6 Domains, No New Malware

A signed VPN/proxy-trojan operation shows zero new malicious binaries this pass, but its network layer keeps expanding. A single TLS certificate serial for *.certfallback.com now spans four hosts across three unrelated carriers in China and the Philippines.

Aug 2, 2026, 21:35 (UTC+9)Last seenAug 2, 2026Severity100ByCTX TeamActorUAC-0063TAG-110IOC75MITRE21

The latest pass through this VPN-and-proxy-trojan operation surfaces ten additional IP addresses and six additional domains — and not a single new malicious binary. That lopsided delta is itself the story. While the signed installers that anchor this campaign have sat unchanged for months, the network layer underneath them keeps expanding, and the clearest evidence of that expansion is a single TLS certificate serial, 363a6b88ee219be351b40934, now confirmed live on four separate hosts spread…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence