CERT Polska links 17 Android apps via a reused TLS certificate
A CERT Polska report dated 23 September 2026 describes linking applications through registration records, DNS structure, object naming and a reused TLS certificate. Six apps contained toll fraud components, 11 more had malicious loaders, and 98 ads point only to advertiser account reuse.
- All 20 parent domains were registered via Amazon Registrar between 10 July and 17 September 2026
- A Let's Encrypt certificate for ablefee.wiki appeared on five IPs from independent loader samples
- Four domains shared identical WHOIS hashes for organisation, phone and address fields
- ZoomEye found 10 services on certificate-sharing addresses and zero for ablefee.wiki
Read next
Security