Uncovering the Chinese Proxy Service Used in APT Campaigns
2025-08-20 • Spur •
https://spur.us/how-spur-uncovered-a-chinese-proxy-and-vpn-service-used-in-an-apt-campaign/
Spur investigated anonymizing infrastructure after a leaked dataset tied IP address 156.59.13[.]153 to activity targeting organizations in South Korea and Taiwan, while the leak author attributed the activity to Kimsuky and Spur explicitly left that attribution unvalidated. The investigation pivoted from a *.appletls[.]com certificate on non-standard port 4012 to more than 1,000 related IPs, mostly in China, and then to Trojan proxy configuration strings found through GitHub research. Those strings referenced ganode[.]org and appletls[.]com, leading Spur to identify WgetCloud, formerly GaCloud, as a commercial VPN/proxy service using the observed certificate pattern. Spur verified the link by purchasing access, retrieving node configurations, and confirming that the reportedly used Singapore IP belonged to WgetCloud infrastructure, illustrating how suspected APT traffic can blend into commercial proxy services.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | appletls.com | 2025-08-20 | 2025-09-01 |
| IPv4 | 156.59.13.153 | 2025-08-20 | 2025-09-01 |
| HASH | a26c0e8b1491eda727fd88b629ce886… | 2025-08-20 | 2025-08-20 |
| DOMAIN | ctax2k93hsocm8mxx6ey.ganode.org | 2025-08-20 | 2025-08-20 |
| DOMAIN | ganode.org | 2025-08-20 | 2025-08-20 |
| DOMAIN | mf429xciejryees2cusm.appletls.c… | 2025-08-20 | 2025-08-20 |