Suspected KEYPLUG Infrastructure: TLS Certificates and GhostWolf Links
ID: b13857cd-83cd-5591-9274-224c2f36ef16
STIX ID: report--b13857cd-83cd-5591-9274-224c2f36ef16
Feed Name: Hunt.io Blog
Threat Score
The report analyzes historical and current TLS certificate data (notably a wolfSSL 'Support_1024' OU and JA4X fingerprint) to identify and track GhostWolf/KEYPLUG infrastructure likely tied to APT41/RedGolf, lists active and historical IP IOCs, demonstrates pivoting via the Hunt platform, and recommends monitoring certificate anomalies and JA4+ TLS fingerprinting to detect similar hostile infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
