logo

Pulling the Thread: Two Unreported Infrastructure Clusters Linked to Chinese Espionage Tooling

ID: 7015ef3c-931b-5c85-b8fb-44536c356858

STIX ID: report--7015ef3c-931b-5c85-b8fb-44536c356858

Feed Name: Plausible Deniablility

Threat Score
78/100

Date Published: 2026-06-23

Date Updated: 2026-08-11

Author: {"name"=>"", "avatar"=>"/assets/images/avatar-round.svg", "bio"=>"Cyber Threat Intelligence. Allegedly.", "links"=>[{"label"=>"Twitter", "icon"=>"fab fa-fw fa-twitter-square", "url"=>"https://twitter.com/4rchib4ld"}, {"label"=>"GitHub", "icon"=>"fab fa-fw fa-github", "url"=>"https://github.com/4rchib4ld"}, {"label"=>"LinkedIn", "icon"=>"fab fa-fw fa-linkedin", "url"=>"https://www.linkedin.com/in/axel-z-9a9a38117/"}]}

...
...

This intelligence post documents two distinct but thematically related infrastructure clusters: an unreported ShadowPad C2 cluster identified by a characteristic HTML body hash and TLS certificate pivots (including domains impersonating Microsoft/Google and an Intel-themed certificate cluster), and an extension of a Winnti ELF cloud-credential-harvester cluster confirmed by two SHA256 sample hashes and Alibaba-lookalike C2 domains. The author provides IOCs with confidence ratings, highlights an overlapping 38.60.x.x block and a cross-find IP linked to historical APT41 reporting, and offers a STIX 2.1 bundle on request while refraining from firm attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.