logo

Connecting Dots with SSL Certificates: Finding Threat Actors with Graph Theory

ID: 4bdb5e9d-51eb-506f-b842-9bf84a36f46a

STIX ID: report--4bdb5e9d-51eb-506f-b842-9bf84a36f46a

Feed Name: Infoblox Blog

Threat Score
70/100

Date Published: 2026-03-04

Date Updated: 2026-04-28

Author: Zafir Ansari

...
...

Infoblox describes a certificate-driven threat-intelligence pipeline that uses Certificate Transparency logs and graph analysis of SSL/TLS SAN fields to link domains into connected components, enabling discovery and prioritization of malicious infrastructure, attribution and consolidation of threat actor identities, and expansion of coverage via association; the report includes concrete discoveries such as a 109-domain Apple lookalike cluster, 174 e-commerce scam sites, RDGA-generated domains, and various crypto/Google/Telegram impersonation domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.