
A 21-Kilobyte Worm Stalls the Sandbox, Then Mails Itself Onward
A record attributed to 'Lazarus Group' turns out to rest on a single verified artifact: a 2019-vintage MyDoom worm that checks for debuggers, stalls execution, and re-mails itself via SMTP while disguised as lsass.exe. The other 40 hashes, seven IPs, and eight domains attached to the record carry no comparable telemetry.

Russian-Registered AS213010 Has Hosted C2 Since 2019
The most durable artifact in this record isn't a binary or a certificate — it's a network. Autonomous System 213010, registered to an entity RIPE lists as "Gening Nikita Dmitrievich," has hosted at least two IP addresses that anchor domains registered three years apart: 87.251.75.204, which carries a domain first registered on 2023-09-20 (poolfreshstep.com), and 80.66.76.210, which is fronting a domain that was only 14 days old when this record closed (bunnysecurityrelay.com, created…

Recycled Sectigo Certificate Links Loader and Banking-Trojan Payload
The same revoked leaf certificate — serial 00 8E 3E 9A 2F E7 3C 91 98 5B 4F 90 D5 95 77 CD 6C, issued under the name MASTER LIM LTD and chained through COMODO RSA Code Signing CA up to Sectigo (formerly Comodo CA) — is stamped on two files that sit at opposite ends of a delivery chain: an NSIS self-extracting installer and the banking-trojan DLL it ultimately drops.

5KB Fake 'update.exe' Stager Ties to Tomiris/YoroTrooper Espionage
A stager built to pass as nothing more than a routine Windows update file is barely large enough to hold its own icon — five kilobytes of packed .NET code, unsigned, dropped straight into C:\Windows\Temp\update.exe. Despite the size, 55 of 76 antivirus engines flag it, and the record ties the sample (4f237b5a…) to the espionage-focused Tomiris and YoroTrooper clusters.
C&CMembersSep 21, 2026, 22:29 (UTC+9)Two Shell Firms, One DigiCert Root: Adware's Signing Trick Repeats
AloneTrayServer.exe and MLPrivacy.exe — two installers newly added to a long-running Chinese adware-distribution cluster — both carry valid, chained code-signing certificates issued to a company calling itself 成都星汉云科科技有限公司. That in itself would be unremarkable. What makes it worth a second look is that this is now the second shell identity CTX Team has traced back to the exact same intermediate certificate authority — DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 — after an earlier…
#code-signingabuse#shellcompanies#DigiCert#adware#Ludashi#T1553.002#sideloading#China-basedinfrastructureIOCf9 · i3 · d4 · u1MITRE45
FILEMembersSep 21, 2026, 14:31 (UTC+9)One 2009 Compile Job Is the Only Real Link in 'Klovbot' Cluster
Everything else in this record is décor around one hard fact: two of the five files carried under a shared feed label share not just a detection verdict but an identical import table hash, an identical rich-header fingerprint, and an identical PE compile timestamp of January 14, 2009. That is not coincidence — it is proof that whoever built the Hiloti/Mufanom downloader compiled it once and shipped it out twice, once packaged as a standalone executable and once as a dynamic-link library, both…
#Klovbot#Hiloti#Mufanom#Buzus#Prolaco#Renos#commoditymalware#malwareclusteringIOCf46 · i1 · d6 · u2MITRE48RegionsUSIndustriesEngineering
FILEMembersSep 21, 2026, 07:04 (UTC+9)Fake Adobe Audition Patch Fans Out Into Two Trojan Families
A pirated license patch for Adobe Audition is doing more work than a typical cracked-software lure. Once a victim runs the fake "Adobe Audition Patch v24.exe," the package drops from an identical temporary-folder fragment — u2pvkyr3.1xh\Patch-Activated\ — into two forensically distinct payloads that VirusTotal resolves under entirely different threat labels: trojan.swisyn/gosys on one branch, trojan.autoit/nymeria on the other.
#crackedsoftwarelure#AutoITdropper#Doeneriumstealer#imphashreuse#JA3fingerprint#node.exemasquerade#CommentCrew/APT1#malwaredistributionActorsComment Crew · Byzantine CandorIOCf48 · i0 · d0 · u0MITRE51RegionsGT
C&CPublicSep 21, 2026, 06:50 (UTC+9)A Two-Tier Certificate Strategy Behind a Freshly Rotating C2 Cluster
Four IP addresses and three domains now tracked under a single command-and-control cluster show something that rarely shows up this cleanly in raw infrastructure data: two entirely different levels of operational care, running side by side on the same campaign. On one tier, listener IPs are still wearing the certificates they shipped with — an OpenSSL install default, a Chinese vendor's untouched template — the kind of TLS hygiene nobody bothers to fix on infrastructure meant to be thrown away.
#command-and-controlinfrastructure#TLScertificatehygiene#wildcardcertificates#dynamicDNS#DGAdomains#unattributedthreatcluster#certificatetransparency#networkinfrastructureanalysisIOCf0 · i4 · d3 · u0MITRE10IndustriesContainers & Packaging
APTMembersSep 21, 2026, 06:32 (UTC+9)Cracked-Software Lure Network Runs on Expired EV Cert, Shared Hosting
Three files sitting in the same threat record advertise themselves as ordinary utility software — a network scanner, a product activator, a WhatsApp data-transfer tool — and all three are wrapped in commercial anti-analysis packing strong enough to blunt most of the engines that inspect them. That combination, not the actor label attached to the record, is the actual story here.
#crackedsoftwarelures#codesigningabuse#VMProtectpacking#maliciousdomaininfrastructure#CloudflareDNSpivot#attributionmismatch#AdvancedIPScannerimpersonation#certificaterotationActorsLockbit GangIOCf3 · i0 · d5 · u0MITRE6IndustriesContainers & Packaging
C&CPublicSep 20, 2026, 22:49 (UTC+9)Emotet 'C2 Servers' Entry Bundles 3 Unrelated IPs, No Shared Fingerprint
A feed entry logged at 00:03 UTC on September 20 groups nine indicators under the category "c2-servers" — a single Emotet loader DLL and three IP addresses spread across Malaysia, Ghana and South Korea. The label implies a working command-and-control triangle behind a live banking-trojan campaign. The evidence inside the record says something closer to the opposite: none of the three IPs share an autonomous system, a certificate, or a registrant record with each other or with the file, and two…
#Emotet#C2infrastructure#bankingtrojan#threatintelligencefeeds#certificatestaleness#Malaysia#Ghana#SouthKoreaIOCf6 · i3 · d0 · u6RegionsUSIndustriesRetail
APTPublicSep 20, 2026, 22:41 (UTC+9)Fake Skype Installer Ran a Full Espionage Chain for a Decade
A Win32 executable that calls itself Skype.exe, carries Skype's product name and a "© 2003-2012 Skype and/or Microsoft" copyright string, and still ships completely unsigned has been circulating in low volumes for more than a decade — first submitted for scanning in October 2014, most recently as March 2025. The file (b6ca1211…8f518a403) is flagged by 61 of 78 engines, a strong consensus that has held steady across its long life.
#Molerats#GazaCybergang#AridViper#Skypemasquerade#trojanizedinstaller#anti-analysisevasion#DNSbeacon#espionagemalwareActorsMolerats · Gaza CybergangIOCf1 · i0 · d1 · u1MITRE9RegionsCN · HKIndustriesRetail
C&CMembersSep 20, 2026, 14:37 (UTC+9)A Hidden Macrosheet Reopens Emotet's Front Door
A spreadsheet flagged as trojan.abracadabra/emotet, submitted for scanning barely a day before this review and already caught by 42 of 75 engines, carries an Excel4 macro built to fire the moment the file opens — and the macro logic itself sits inside a sheet the workbook keeps hidden from anyone who opens it in Excel. Two named detections establish this precisely: the YARA rule `SUSP_Excel4Macro_AutoOpen matches the auto-executing macro trigger, and Microsoft_Excel_Hidden_Macrosheet` catches…
#Emotet#TA542#Excel4macro#hiddenmacrosheet#DridexJA3fingerprint#Zenpakloader#retailsector#crimewareinfrastructureActorsEmotet Group · TA542IOCf5 · i3 · d1 · u6RegionsUSIndustriesRetail
APTMembersSep 20, 2026, 14:29 (UTC+9)Fake WebView2 DLL Stalls Sandboxes to Outwait Detection
A DLL calling itself WebView2Loader.dll — the file Microsoft's own browser-embedding runtime uses on tens of millions of Windows machines — turns out to be a 3,544KB Win32 payload that checks for an attached debugger, stalls execution for long stretches, waits for a human to actually touch the keyboard, and probes the BIOS before doing anything else.
#WebView2masquerade#SalatStealer#Vidar#Snowglobe#Varistpacker#sandboxevasion#Let'sEncryptcertificaterotation#retailsectortargetingActorsSnowglobe · Animal FarmIOCf45 · i2 · d1 · u2RegionsUSIndustriesRetail
- Articles published
- 608
- IOCs analysed
- 20,676
- Threat Actor
- 451
- MITRE techniques
- 209
- Targeted regions
- 157
- Targeted industries
- 32