2025-01-23 (Back to Inventory)

Mapping Suspected KEYPLUG Infrastructure: TLS Certificates, GhostWolf, and RedGolf/APT41 Activity

Author(s): Hunt.io
Organization: Hunt.io
elf.keyplug

Open article directly   Open article on Archive.org  

Related Articles

2026-03-17Hunt.ioHunt.io
Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2
2026-03-11Hunt.ioHunt.io
Operation Roundish: Uncovering an APT28 Roundcube Toolkit Used Against Ukrainian Government Targets
2026-03-04Hunt.ioHunt.io
Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation