Unmasking Adversary Infrastructure: How Certificates and Redirects Exposed Earth Baxia and PlugX Activity
ID: 18a98127-1e0f-531d-b5f8-e3bbfb6b9a18
STIX ID: report--18a98127-1e0f-531d-b5f8-e3bbfb6b9a18
Feed Name: Hunt.io Blog
The report details an investigation that uncovered two separate malicious infrastructure clusters: a 12-node network attributed to Earth Baxia using suspicious Cloudflare and fake Microsoft certificates and HTTP 301 redirects to high-profile sites, and a 5-node cluster linked to PlugX based on certificate OUs containing "AES" and HTTP 302 redirects to Google. It lists IOCs (IP addresses, domains, certificates, redirect URLs), illustrates detection queries, and highlights certificate and HTTP-header anomalies as the primary TTPs used to identify and track the networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
