logo

DarkPeony’s Trail: Certificate Patterns Point to Sustained Campaign Infrastructure

ID: 403993e9-59c1-50ea-a5fe-9cc298e4da0e

STIX ID: report--403993e9-59c1-50ea-a5fe-9cc298e4da0e

Feed Name: Hunt.io Blog

Threat Score
82/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This analysis expands on previously reported DarkPeony infrastructure associated with PlugX: investigators identified multiple IPs, domains, and SSL certificate patterns (notably 'AES' in OU and CloudFlare origin certs) used to hide C2 and malware distribution. The report links a malicious 'Meeting Invitation.msc' sample to domains (e.g., vabercoach.com, loginge.com), lists IPs, ASNs and certificate hashes as network observables, and offers a JARM/subject CN query to help defenders hunt for related CloudFlare-origin certificates and emerging infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.