logo

Suspected KEYPLUG Infrastructure: TLS Certificates and GhostWolf Links

ID: b13857cd-83cd-5591-9274-224c2f36ef16

STIX ID: report--b13857cd-83cd-5591-9274-224c2f36ef16

Feed Name: Hunt.io Blog

Threat Score
82/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

The report analyzes historical and current TLS certificate data (notably a wolfSSL 'Support_1024' OU and JA4X fingerprint) to identify and track GhostWolf/KEYPLUG infrastructure likely tied to APT41/RedGolf, lists active and historical IP IOCs, demonstrates pivoting via the Hunt platform, and recommends monitoring certificate anomalies and JA4+ TLS fingerprinting to detect similar hostile infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.