Unmasking Adversary Infrastructure: How Certificates and Redirects Exposed Earth Baxia and PlugX Activity
hunt.io | blog | #threat-intelligence | #apt | #redirects | #tls-certificates | #plugx | #earth-baxia
Summary
Hunt.io maps two malicious server clusters—Earth Baxia and suspected PlugX—found via anomalous Cloudflare certificates, fake 'Microsoft' self-signed certs and 301 redirects to FBI, NASA and eBay.
- Published
- Collected
Skip to content