logo

Unmasking Adversary Infrastructure: How Certificates and Redirects Exposed Earth Baxia and PlugX Activity

ID: 18a98127-1e0f-531d-b5f8-e3bbfb6b9a18

STIX ID: report--18a98127-1e0f-531d-b5f8-e3bbfb6b9a18

Feed Name: Hunt.io Blog

Threat Score
72/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

The report details an investigation that uncovered two separate malicious infrastructure clusters: a 12-node network attributed to Earth Baxia using suspicious Cloudflare and fake Microsoft certificates and HTTP 301 redirects to high-profile sites, and a 5-node cluster linked to PlugX based on certificate OUs containing "AES" and HTTP 302 redirects to Google. It lists IOCs (IP addresses, domains, certificates, redirect URLs), illustrates detection queries, and highlights certificate and HTTP-header anomalies as the primary TTPs used to identify and track the networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.