⚠️ Threat Intelligence Update | Plump Spider
A new TLS certificate (ID 25238705005) was issued on March 26, 2026 for the domain
aut-bank.com (including wildcard *.aut-bank.com). This domain is confirmed as Command and Control (C2) infrastructure of the Brazilian threat ponsible for large-scale silent Pix fraud operations (pacs.008).
🔗 Certificate Transparency Query
crt.shZ):
crt.sh/?id=25238705005W
🔗 Detailed analysis linkin
aut-bank.com7t to Plump Spider (Medium @ggabrielhd – IOCs, TTPs and 2026 Pix campaign)
medium.com/@ggabrielhd/po…yg
Intelligence Insights
• Indicates active C2 infrastructure rotation and real-time maintenance (issued less than 48 hours ago).
• High-confidence linkage to silent financial intrusions targeting banks, insurers, retail, and SPI/Pix integrators in Brazil.
• Use of Cloudflare + Google Trust Services demonstrates professional OPSEC and rapid evasion capabilities.
Detection Triggers (Activate Immediately)
• Any TLS traffic t
aut-bank.com7t or any subdomain *.aut-bank.com
• Connections to IP 24.152.36.138 (ASN 270564 – Brazil)
• Recent certificates matching DGA patterns
yrf.comMy,
kqe.comGd,
rff.comI0) or JA3S fingerprint 15af977ce25de452b96affa2addb1036
Proactive monitoring is strongly recommended in firewall, proxy, and HSM logs
.
#ThreatIntelligenc
e #CyberSecurit
y #PlumpSpide
r #PixFrau
d #C2Monitorin
g #OSIN
T #BrazilCyberSecurit
y #FinancialThreatActor