FILEMembersSep 22, 2026, 22:34 (UTC+9)Recycled Sectigo Certificate Links Loader and Banking-Trojan Payload
The same revoked leaf certificate — serial 00 8E 3E 9A 2F E7 3C 91 98 5B 4F 90 D5 95 77 CD 6C, issued under the name MASTER LIM LTD and chained through COMODO RSA Code Signing CA up to Sectigo (formerly Comodo CA) — is stamped on two files that sit at opposite ends of a delivery chain: an NSIS self-extracting installer and the banking-trojan DLL it ultimately drops.
#TA505#LDPinchbanker#Sectigocodesigningabuse#NSISinstaller#VBScriptstager#sandboxevasion#DGAdomains#bankingtrojanActorsTA505 · Hive0065IOCf5 · i0 · d2 · u4MITRE37RegionsCH · USIndustriesRetail · Support Services
FILEMembersSep 22, 2026, 14:47 (UTC+9)5KB Fake 'update.exe' Stager Ties to Tomiris/YoroTrooper Espionage
A stager built to pass as nothing more than a routine Windows update file is barely large enough to hold its own icon — five kilobytes of packed .NET code, unsigned, dropped straight into C:\Windows\Temp\update.exe. Despite the size, 55 of 76 antivirus engines flag it, and the record ties the sample (4f237b5a…) to the espionage-focused Tomiris and YoroTrooper clusters.
#Tomiris#YoroTrooper#AgentTesla#.NETstager#anti-debuggingevasion#Let'sEncryptcertificateabuse#VDSINAVPShosting#espionagemalwareActorsTomiris · YoroTrooperIOCf1 · i1 · d0 · u1MITRE12RegionsCH · JO · USIndustriesGovernment · Retail · Support Services
C&CMembersSep 21, 2026, 22:29 (UTC+9)Two Shell Firms, One DigiCert Root: Adware's Signing Trick Repeats
AloneTrayServer.exe and MLPrivacy.exe — two installers newly added to a long-running Chinese adware-distribution cluster — both carry valid, chained code-signing certificates issued to a company calling itself 成都星汉云科科技有限公司. That in itself would be unremarkable. What makes it worth a second look is that this is now the second shell identity CTX Team has traced back to the exact same intermediate certificate authority — DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 — after an earlier…
#code-signingabuse#shellcompanies#DigiCert#adware#Ludashi#T1553.002#sideloading#China-basedinfrastructureIOCf9 · i3 · d4 · u1MITRE45
FILEMembersSep 21, 2026, 14:31 (UTC+9)One 2009 Compile Job Is the Only Real Link in 'Klovbot' Cluster
Everything else in this record is décor around one hard fact: two of the five files carried under a shared feed label share not just a detection verdict but an identical import table hash, an identical rich-header fingerprint, and an identical PE compile timestamp of January 14, 2009. That is not coincidence — it is proof that whoever built the Hiloti/Mufanom downloader compiled it once and shipped it out twice, once packaged as a standalone executable and once as a dynamic-link library, both…
#Klovbot#Hiloti#Mufanom#Buzus#Prolaco#Renos#commoditymalware#malwareclusteringIOCf46 · i1 · d6 · u2MITRE48RegionsUSIndustriesEngineering
FILEMembersSep 21, 2026, 07:04 (UTC+9)Fake Adobe Audition Patch Fans Out Into Two Trojan Families
A pirated license patch for Adobe Audition is doing more work than a typical cracked-software lure. Once a victim runs the fake "Adobe Audition Patch v24.exe," the package drops from an identical temporary-folder fragment — u2pvkyr3.1xh\Patch-Activated\ — into two forensically distinct payloads that VirusTotal resolves under entirely different threat labels: trojan.swisyn/gosys on one branch, trojan.autoit/nymeria on the other.
#crackedsoftwarelure#AutoITdropper#Doeneriumstealer#imphashreuse#JA3fingerprint#node.exemasquerade#CommentCrew/APT1#malwaredistributionActorsComment Crew · Byzantine CandorIOCf48 · i0 · d0 · u0MITRE51RegionsGT
C&CPublicSep 21, 2026, 06:50 (UTC+9)A Two-Tier Certificate Strategy Behind a Freshly Rotating C2 Cluster
Four IP addresses and three domains now tracked under a single command-and-control cluster show something that rarely shows up this cleanly in raw infrastructure data: two entirely different levels of operational care, running side by side on the same campaign. On one tier, listener IPs are still wearing the certificates they shipped with — an OpenSSL install default, a Chinese vendor's untouched template — the kind of TLS hygiene nobody bothers to fix on infrastructure meant to be thrown away.
#command-and-controlinfrastructure#TLScertificatehygiene#wildcardcertificates#dynamicDNS#DGAdomains#unattributedthreatcluster#certificatetransparency#networkinfrastructureanalysisIOCf0 · i4 · d3 · u0MITRE10IndustriesContainers & Packaging
APTMembersSep 21, 2026, 06:32 (UTC+9)Cracked-Software Lure Network Runs on Expired EV Cert, Shared Hosting
Three files sitting in the same threat record advertise themselves as ordinary utility software — a network scanner, a product activator, a WhatsApp data-transfer tool — and all three are wrapped in commercial anti-analysis packing strong enough to blunt most of the engines that inspect them. That combination, not the actor label attached to the record, is the actual story here.
#crackedsoftwarelures#codesigningabuse#VMProtectpacking#maliciousdomaininfrastructure#CloudflareDNSpivot#attributionmismatch#AdvancedIPScannerimpersonation#certificaterotationActorsLockbit GangIOCf3 · i0 · d5 · u0MITRE6IndustriesContainers & Packaging
C&CPublicSep 20, 2026, 22:49 (UTC+9)Emotet 'C2 Servers' Entry Bundles 3 Unrelated IPs, No Shared Fingerprint
A feed entry logged at 00:03 UTC on September 20 groups nine indicators under the category "c2-servers" — a single Emotet loader DLL and three IP addresses spread across Malaysia, Ghana and South Korea. The label implies a working command-and-control triangle behind a live banking-trojan campaign. The evidence inside the record says something closer to the opposite: none of the three IPs share an autonomous system, a certificate, or a registrant record with each other or with the file, and two…
#Emotet#C2infrastructure#bankingtrojan#threatintelligencefeeds#certificatestaleness#Malaysia#Ghana#SouthKoreaIOCf6 · i3 · d0 · u6RegionsUSIndustriesRetail
APTPublicSep 20, 2026, 22:41 (UTC+9)Fake Skype Installer Ran a Full Espionage Chain for a Decade
A Win32 executable that calls itself Skype.exe, carries Skype's product name and a "© 2003-2012 Skype and/or Microsoft" copyright string, and still ships completely unsigned has been circulating in low volumes for more than a decade — first submitted for scanning in October 2014, most recently as March 2025. The file (b6ca1211…8f518a403) is flagged by 61 of 78 engines, a strong consensus that has held steady across its long life.
#Molerats#GazaCybergang#AridViper#Skypemasquerade#trojanizedinstaller#anti-analysisevasion#DNSbeacon#espionagemalwareActorsMolerats · Gaza CybergangIOCf1 · i0 · d1 · u1MITRE9RegionsCN · HKIndustriesRetail
C&CMembersSep 20, 2026, 14:37 (UTC+9)A Hidden Macrosheet Reopens Emotet's Front Door
A spreadsheet flagged as trojan.abracadabra/emotet, submitted for scanning barely a day before this review and already caught by 42 of 75 engines, carries an Excel4 macro built to fire the moment the file opens — and the macro logic itself sits inside a sheet the workbook keeps hidden from anyone who opens it in Excel. Two named detections establish this precisely: the YARA rule `SUSP_Excel4Macro_AutoOpen matches the auto-executing macro trigger, and Microsoft_Excel_Hidden_Macrosheet` catches…
#Emotet#TA542#Excel4macro#hiddenmacrosheet#DridexJA3fingerprint#Zenpakloader#retailsector#crimewareinfrastructureActorsEmotet Group · TA542IOCf5 · i3 · d1 · u6RegionsUSIndustriesRetail
APTMembersSep 20, 2026, 14:29 (UTC+9)Fake WebView2 DLL Stalls Sandboxes to Outwait Detection
A DLL calling itself WebView2Loader.dll — the file Microsoft's own browser-embedding runtime uses on tens of millions of Windows machines — turns out to be a 3,544KB Win32 payload that checks for an attached debugger, stalls execution for long stretches, waits for a human to actually touch the keyboard, and probes the BIOS before doing anything else.
#WebView2masquerade#SalatStealer#Vidar#Snowglobe#Varistpacker#sandboxevasion#Let'sEncryptcertificaterotation#retailsectortargetingActorsSnowglobe · Animal FarmIOCf45 · i2 · d1 · u2RegionsUSIndustriesRetail
C&CMembersSep 20, 2026, 06:37 (UTC+9)Adware Operator Recycles Qihoo, Alibaba, UnionPay TLS Certs on Carrier IPs
Four subdomains under a single Chinese apex — adblock.yunkeit.com, cdn-ali-v3.yunkeit.com, stat.yunkeit.com and upgrade.yunkeit.com — were all registered on the same day, 2025-09-11, through the Hichina registrar (grs-whois.hichina.com, nameservers DNS23/24.HICHINA.COM). Three of the four resolve to the identical A-record, 47.94.14.179, and the fourth, cdn-ali-v3.yunkeit.com, fans out across an eight-address block (180.163.147.83 through .90) behind a CNAME to w.kunluncan.com.
#yunkeit.com#codesigningabuse#TLScertificaterecycling#ChinaMobile#adwaredistribution#Ludashi#DLLside-loading#PUAbundlerIOCf8 · i11 · d4 · u3MITRE36
APTMembersSep 20, 2026, 06:28 (UTC+9)VPN Trojan Trio Shares Revoked EV Signature, Clears Sandbox Despite Flags
Three Windows binaries branded as pieces of a consumer VPN client — a small stub called wire.exe, a much larger DLL called wire.dll, and a standalone installer called upWire.exe — all carry the identical publisher chain: WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained up through GlobalSign GCC R45 EV CodeSigning CA 2020 to GlobalSign's root.
#Cactus#ramnitActorsCactus · Cactus Ransomware GroupIOCf33 · i5 · d9 · u2MITRE20
APTMembersSep 19, 2026, 22:37 (UTC+9)Same Packer, Four Years: Gh0st RAT Toolchain Refuses to Retool
Three Farfli/Gh0st droppers submitted four years apart — one first seen in April 2022, two more that surfaced fresh on September 18, 2026 — carry the identical PEiD packing signature and trip the same Elastic-authored detection logic, a rule called Windows_Trojan_Generic_9e4bb0ce. That kind of toolchain stasis, more than any single new sample, is the story in this cluster: an operator that built a packer wrapper and a Gh0st-derivative payload once and has evidently seen no operational need to…
#SaltySpider#Gh0stRAT#Farfli#rootkitdriver#code-signingcertificateabuse#sandboxevasion#credentialdumping#commandandcontrolinfrastructureActorsSalty Spider · KuKuIOCf14 · i0 · d1 · u3MITRE30RegionsUSIndustriesRetail
FILEMembersSep 19, 2026, 06:42 (UTC+9)Remcos RAT Sample Stalls Sandboxes, Checks for Debuggers
A 92-kilobyte Windows executable now flagged by 64 of 74 antivirus engines carries one of the most heavily fingerprinted commodity RATs in current circulation — and it does so with a textbook anti-analysis playbook baked in before it ever reveals its payload. The dropper, tracked here as d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867, is unsigned, packed with PEiD, and — according to three independent sandboxes that returned a unanimous malicious verdict — runs as Remcos, the…
#RemcosRAT#GorgonGroup#Subaat#sandboxevasion#anti-debugging#UACbypass#gambling-luredomains#commoditymalwareActorsGorgon Group · SubaatIOCf1 · i0 · d3 · u2MITRE11
C&CMembersSep 19, 2026, 06:33 (UTC+9)New Iranian IP Completes Matched Amadey C2 Pair on AS44208
A new IP address surfaced in the latest sweep of this Amadey-and-RedLine crimeware cluster, and it doesn't open a new front — it closes a loop. 176.46.152.47 sits one address away from 176.46.152.46, both inside the same /22 block registered to Farahoosh Dena PLC under AS44208 in Iran, and both now confirmed serving the identical panel path, `/diamo/data.php, alongside a shared payload filename, /zx.exe.
#Amadey#RedLineStealer#ClipBanker#C2infrastructure#Iran#FarahooshDenaPLC#forgedcodesigning#crimewareIOCf14 · i3 · d0 · u20MITRE55RegionsUSIndustriesRetail
APTMembersSep 18, 2026, 23:05 (UTC+9)Aged 2018 Domain Repointed to Fresh Emotet C2 in Turkey
A domain registered back in April 2018 — long enough to have aged out of any registrar-freshness scrutiny — currently resolves to a command-and-control IP that was flagged for the first time on 2026-09-18. The domain is atici.net, and its single A-record points to 185.15.196.157, a Turkish address on AS201520 (Dedicated Telekomunikasyon Teknoloji Hiz. Tic. San. LTD. STI., Istanbul) that carries a Let's Encrypt certificate minted only weeks earlier.
#Emotet#TA542#Excel4macro#command-and-controlinfrastructure#Let'sEncryptcertificates#domainagelaundering#Turkishhosting#retailsectortargetingActorsEmotet Group · TA542IOCf1 · i2 · d3 · u2RegionsUSIndustriesRetail
FILEMembersSep 18, 2026, 14:36 (UTC+9)Sandbox Clears It, 26 Engines Don't: Allaple's Acrobat HTML Ruse
A dropper posing as an Adobe Acrobat DC interface resource carries the file name "index.html" and sits, according to its own embedded path reference, inside C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\index.html. Twenty-six of 77 engines on VirusTotal flag it as trojan.allaple. A single sandbox run on the same file, however, returned a "harmless" verdict at 99% confidence.
#Allaple#trojan.allaple#AdobeAcrobatDCmasquerade#sandboxevasion#staticvsdynamicdetection#MaxfonSrlnetblock#ItalyISPinfrastructure#packedPE32IOCf33 · i41 · d0 · u0MITRE12RegionsUSIndustriesRetail
C&CMembersSep 18, 2026, 14:27 (UTC+9)Four Disposable-Infrastructure Playbooks Share One Sharktech Backbone
A c2-servers indicator set logged by CTX Team's telemetry on 18 September carries not a single malicious file — no hash, no PE, no sandbox verdict anywhere in it. What it does carry is five IPs and eight domains, and inside that narrow footprint sit four distinct, professionally executed infrastructure playbooks running side by side: a single Let's Encrypt certificate stretched across eight numeric look-alike domains, a same-day-registered Cloudflare-fronted subdomain pair, a same-day…
#Sharktechhosting#Cloudflarefronting#fast-fluxDNS#dynamicDNSrotation#Let'sEncryptcertificatereuse#bulletproofhosting#phishinginfrastructure#containersandpackagingsectorIOCf0 · i5 · d8 · u0MITRE14IndustriesContainers & Packaging
FILEPublicSep 18, 2026, 06:57 (UTC+9)MuddyWater Loader Skips DNS, Curls Straight to a Bare IP
A Windows loader flagged as trojan.donut/dump by 57 of 75 engines is issuing outbound HTTP requests with a curl-style user agent straight to a numeric IP address rather than a resolved domain — a pattern four separate community intrusion-detection rules independently caught on the same sample. The same binary checks the CPU timer before running, a classic sandbox-timing test, and loads additional modules only after that check clears.
#MuddyWater#Seedworm#donutloader#C2tobareIP#sandboxevasion#HostSailorLtd#espionage#in-memoryexecutionActorsMuddyWater · TEMP.ZagrosIOCf3 · i1 · d0 · u1MITRE36RegionsCN
FILEMembersSep 17, 2026, 14:29 (UTC+9)Phorpiex Drop Point Holds Steady as Yemeni Telecom ASN Absorbs New Churn
The most interesting fact in this snapshot of a long-running Phorpiex/Kadrbot cluster isn't a new payload — it's what didn't change. The bare-IP delivery host that anchored CTX Team's earlier look at this cluster, 185.215.113.84, still serves the same six sequentially numbered /twizt/1 through /twizt/6 paths it did before, sitting at 16 of 89 security-vendor detections on VirusTotal.
#Phorpiex#Kadrbot#YementelecomASN#Seychelleshosting#bare-IPdelivery#Xmrigcryptomining#wormdownloader#maliciousfilehashesIOCf4 · i4 · d0 · u7MITRE37RegionsAF · ROIndustriesHealthcare
APTMembersSep 17, 2026, 06:29 (UTC+9)One Blank TLS Certificate Links Four Unrelated Cloud Networks
Thirteen IP addresses spread across a hyperscale social-media company's own network, a discount VPS reseller with points of presence on four continents, and two little-known hosting shells registered in Russia all present the exact same self-signed TLS certificate — serial 1acf3e37b37910d932ea64e6bb27615d6484c07d, with both its issuer and subject fields rendered as the literal string "NONE." That certificate, valid from March 2024 through March 2034, is not the kind of artefact that shows up…
#WireVPN#VPNMaster#codesigningabuse#sandboxevasion#Zenlayer#Bytedanceinfrastructure#self-signedcertificate#commoditymalwaredistributionActorsSpace Pirates · WebwormIOCf70 · i22 · d4 · u0MITRE22
C&CMembersSep 16, 2026, 22:53 (UTC+9)Shared Panel Path Ties Five Rebranded Stealers to One C2 Backend
Eleven Windows payloads carrying five different VirusTotal threat labels — Amadey/Lumma, Stealc, ClipBanker/Cerbu, Kasidet/Fragtor, and Barys — all check in with the same small cluster of IP addresses using a verbatim-identical control-panel path. That's not a coincidence of naming; it's a shared backend wearing five different masks, and it's the detail that makes this cluster worth a second look rather than five separate incident tickets. The path reuse is concrete and traceable.
#Stealc#Amadey#Lumma#ClipBanker#Kasidet#Barys#AS214351#commoditymalwareC2IOCf13 · i5 · d2 · u15MITRE60RegionsBA
APTMembersSep 16, 2026, 22:43 (UTC+9)Downloader Stacks Three Evasion Tricks, Hides C2 in Alibaba DoH Traffic
A downloader carrying the threat label trojan.sfuzuan/convagent packs three separate anti-analysis tricks into a single unsigned Windows binary — a debugger check, a deliberate stall before execution, and a 32-to-64-bit mode transition known as HeavensGate — and then leans on Alibaba's own DNS-over-HTTPS infrastructure to resolve whatever it talks to next.
#trojan.sfuzuan#convagent#HeavensGate#DNS-over-HTTPS#GoldEvergreen#BusinessClub#DGAdomains#downloaderevasionActorsGold Evergreen · Business ClubIOCf5 · i0 · d7 · u2
C&CMembersSep 16, 2026, 14:31 (UTC+9)Bright Data-Signed Proxy SDK Joins Signed VPN-Trojan Pipeline
Two freshly signed executables — a proxy updater called net_updater.exe and a companion labelled idle_report.exe (2b7c3cdca1fd951c…), both carrying a Bright Data Ltd certificate and both first submitted just seventeen days before this review — have surfaced inside a signed-installer distribution pipeline CTX Team has continued to track.
#WireVPN#VPNMaster#BrightData#LuminatiproxySDK#code-signingabuse#sandboxevasion#residentialproxymonetization#signed-installerdistributionActorsCactus · Cactus Ransomware GroupIOCf17 · i14 · d30 · u9MITRE19
FILEMembersSep 16, 2026, 06:44 (UTC+9)Adware Installer With Decade-Expired Cert Wrongly Tagged as Lazarus
An adware installer first signed in January 2014 is still circulating with a code-signing certificate that has been invalid for roughly a decade — and the trust chain still resolves cleanly enough that antivirus engines are split on what to do with it. The file, publicly known under the generic name Installer.exe (c5a1140f6de397ad…), carries a signature block reading "Amonetize ltd.; Thawte Code Signing CA - G2; thawte" [T1553.002], but the leaf certificate's own status field says plainly:…
#LazarusGroup#phandoor#code-signingabuse#adwarebundleware#command-and-controlinfrastructure#Amonetize#Let'sEncryptcertificate#pay-per-installActorsLazarus Group · Hastati GroupIOCf1 · i0 · d1 · u2MITRE13RegionsES · VNIndustriesTelecommunications
FILEMembersSep 15, 2026, 22:33 (UTC+9)20-File Kit Bundles Mimikatz, Revoked Driver, PrintNightmare Exploit
A 20-file dossier tracked by CTX Team reads less like a single implant and more like a toolbox someone packed once and shipped intact. At its center sits the open-source mimikatz credential dumper in its signed 2.2.0.0 release form, flanked by a kernel driver still carrying a certificate its own issuer revoked years ago, a bundled exploit module for the PrintNightmare spooler flaw (CVE-2021-1675), and five Nirsoft password-recovery utilities packed with an identical fingerprint and staged in…
#mimikatz#PrintNightmare#CVE-2021-1675#Nirsoftutilities#credentialtheft#revokedcode-signingcertificate#Sandworm#APT27ActorsSandworm · QuedaghIOCf34 · i0 · d0 · u0MITRE28RegionsBRIndustriesManufacturing
FILEMembersSep 15, 2026, 14:58 (UTC+9)A Fifteen-Year-Old Virus Still Rides a Fresh HTML Template
A Sality file infector first captured in mid-2010 is still circulating today, and the html page delivering it isn't old at all — it's a template reused just eight months apart, sitting at zero detections both times. The pairing is the real story here: a payload so well-documented that 56 of 76 engines flag it on sight, fed through a delivery artifact so unremarkable that VirusTotal's entire detection industry walks past it.
#Sality#badcrypt#salload#SaltySpider#polymorphicmalware#HTMLdropper#USBautorunspread#TofseeJA3fingerprintActorsSalty Spider · KuKuIOCf20 · i2 · d1 · u0RegionsUS
C&CMembersSep 15, 2026, 14:49 (UTC+9)Signed and Trusted: Two Malware Families Ride Valid Certs
Four executables signed with a fully valid Bright Data Ltd certificate — the kind of code-signing chain that is supposed to reassure a user they are installing legitimate software — carry threat labels ranging from hacktool and PUA to adware and downloader, and one of them was flagged outright by a sandbox as a stealer. The file, an 11.5MB installer named net_updater.exe (909f62b450…), returned a malicious verdict with the classification "STEALER" and the family name "PBot," despite presenting…
#BrightDataSDK#PBotstealer#wirevpn/jumpertrojan#code-signingabuse#residentialproxyabuse#revokedEVcertificate#templatedTLSinfrastructure#VPNtrojandistributionActorsCactus · Cactus Ransomware GroupIOCf21 · i19 · d30 · u9MITRE18
FILEMembersSep 14, 2026, 22:58 (UTC+9)One Bundler, Four Fake Names, an APT28 Label That Doesn't Fit
A single Win32 installer, 4.4 megabytes, has spent the past two years circulating under at least four different identities — a PingInfoView update, a Roblox Player installer, a Portuguese file-renaming tool called "renomear-tudo," and a Microsoft PC Manager setup package. All four are the same binary (imphash bdc39b1d…), repackaged under different display names and reused across 1,644 separate submissions from 1,438 unique sources.
#APT28misattribution#adwarebundler#codesigningcertificateabuse#malvertisingredirectinfrastructure#EnigmaProtectorpacker#pay-per-install#commoditycrimeware#Let'sEncryptcertificateabuseActorsAPT28 · StrontiumIOCf2 · i1 · d3 · u5MITRE11IndustriesUtilities
APTMembersSep 14, 2026, 22:38 (UTC+9)TA505 Loader Hides Behind Six-Year-Old Mozambique Academic Domain
The most telling artifact in this cluster isn't a binary — it's a URL. rcf.co.mz/mytimeiswriten.exe sits on a domain registered on 2020-05-03 through Mozambique's academic CIUEM Registrar, a domain that still carries active mail routing and a valid SPF record naming its own hosting IP. Rather than spinning up a fresh, throwaway domain that would trip every newly-registered-domain heuristic on the market, whoever is running this operation appears to have repurposed six years of accumulated…
#TA505#Hive0065#rockloader#DuckDNS#Let'sEncryptcertificaterotation#Mozambiquedomainabuse#dynamicDNSC2#bulletproofhostingActorsTA505 · Hive0065IOCf55 · i2 · d1 · u2RegionsDE · ID · IE · ITIndustriesConstruction · Education & Research · Manufacturing
C&CMembersSep 13, 2026, 22:30 (UTC+9)A Redirect Node With No Name: Certificate Cycling Masks a 2014 Dropper
A domain buried inside a routine C2-infrastructure record — baktus.kilu.de — is not serving its own website. Query it over TLS and the certificate that comes back carries the subject name redirect.subdomain.com, a string that points nowhere near the domain a browser actually requested. That mismatch is the clearest single artefact in this record: it marks the node as a relay hop inside a shared hosting fabric, not an independent site with its own identity.
#invoiceluremalware#Let'sEncryptcertificatecycling#wildcardSANabuse#redirectorinfrastructure#overlaydataPE#billingfraudphishing#C2domainrotation#unattributedclusterIOCf10 · i3 · d16 · u7MITRE23RegionsGB · ROIndustriesTechnology
FILEMembersSep 13, 2026, 15:10 (UTC+9)Revoked EV Certificate Still Signs Fake-VPN Malware for Months
A loader-and-updater trio still carries a fully valid-looking code signature from an EV certificate that VirusTotal has explicitly marked revoked — and the operators kept building new samples under that same signing identity for roughly four months after the revocation took hold. Three files — a sideloaded DLL, its companion loader, and an updater binary that installs to C:\Windows\SysWOW64\wire\ — are signed end to end as WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained up through a GlobalSign…
#WEILAINetworkTechnology#revokedEVcertificate#wirevpnloader#VPNMasterdeceptor#BrightDataSDKabuse#codesigningabuse#fakeVPNmalware#APT15ActorsAPT15 · ROYALAPTIOCf8 · i2 · d3 · u0MITRE24IndustriesFood & Beverages
C&CMembersSep 13, 2026, 15:00 (UTC+9)Decade-Old GameOver Zeus DGA Signature Still Catching Live Malware
Ten Snort and Emerging Threats alerts fired against a 13-kilobyte Windows executable disguised as a courier tracking notice — five of them the exact same rule, "MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected." That rule was written for GameOver Zeus, the peer-to-peer variant of the Zeus banking trojan that law enforcement spent years trying to dismantle starting in 2014.
#Zeus#ZBot#GameOverZeus#domaingenerationalgorithm#Let'sEncryptcertificates#PEiDpacker#commandandcontrol#credentialtheftIOCf5 · i2 · d20 · u6MITRE16RegionsRO
C&CMembersSep 13, 2026, 06:52 (UTC+9)Shared TLS Certificate Links Hong Kong IP to Front Domain in C2 Set
Nine domains and four IP addresses tagged as command-and-control infrastructure share almost nothing in common — different registrars, different countries, different certificate authorities — except for one pairing that stands out precisely because it shouldn't exist by coincidence. The IP address 45.154.14.190, registered to MOACK.Co.LTD under AS 138195 in Hong Kong, presents a TLS certificate whose subject and subject-alternative-name field read "anfangshen.com" and "*.anfangshen.com." The…
#commandandcontrolinfrastructure#TLScertificateabuse#Let'sEncrypt#BrightData#PBotstealer#Cactusransomwaregroup#phishingdomains#codesigningabuseActorsCactus · Cactus Ransomware GroupIOCf1 · i4 · d9 · u1MITRE7IndustriesManufacturing · Telecommunications
APTMembersSep 12, 2026, 22:27 (UTC+9)APT33-Linked Downloader Wears a Dead Code-Signing Chain
A trojan tracked as bsymem — publicly also known as Donoff — ships with an entire three-tier code-signing chain still attached to the binary: GlassWire, a legitimate desktop network-monitoring vendor, sitting underneath a Symantec Class 3 SHA256 Code Signing CA certificate and a root VeriSign certificate. VirusTotal's verdict on that chain is blunt — "the digital signature of the object did not verify" — and two of the three certificates in it are separately flagged as "not time valid." The…
#APT33#bsymem#Donoff#AutoITdownloader#codesigningabuse#customermgmt.net#sandboxevasion#masqueradingActorsAPT33 · MagnalliumIOCf3 · i0 · d1 · u1MITRE24RegionsCH · JOIndustriesGovernment · Support Services
FILEMembersSep 12, 2026, 14:56 (UTC+9)Pterodo Backdoor Hides Inside Fake Blender Install Path
A Windows DLL flagged as trojan.pterodo/doina installs itself under a filepath that reads like a legitimate Blender Foundation component — C:\Program Files\Blender Foundation\Blender\A562C7DBA738DC65D3B7DEADE7FFC31D — a GUID-style filename sitting inside a real 3D-graphics software directory rather than a temp folder or a randomly generated string in %APPDATA%.
#Pterodo#Gamaredon#Shuckworm#backdoorDLL#systembinaryproxyexecution#malwaremasquerading#C2infrastructure#espionagemalwareActorsGamaredon Group · CTIGIOCf2 · i0 · d1 · u0MITRE9RegionsCH · CNIndustriesSupport Services
FILEMembersSep 12, 2026, 06:50 (UTC+9)Aged GoDaddy Domains Get Synced Certs, Front 2018 Macro Downloader
Two domains that have sat quietly under GoDaddy registration since the mid-2000s were both re-fronted with brand-new Let's Encrypt certificates within about five weeks of each other in mid-2026 — dthakar.com and elmodular.com, ages 19 and 20 years respectively, neither showing any sign of active legitimate use in that span. A third node, eatspam.co.uk, and its sole resolving address, 45.158.164.138, picked up matching certificates from the same issuer pool on an overlapping schedule.
#EmotetGroup#w97m/emodldr#macrodownloader#Let'sEncryptcertificateabuse#domainhijacking#GoDaddy#WMIexecution#recycledhostinginfrastructureActorsEmotet Group · TA542IOCf3 · i1 · d3 · u6
APTMembersSep 11, 2026, 23:46 (UTC+9)Installer Hides Its Only Flagged File Among Ten Clean Decoys
Ten PNG and CSS files with an identical creation moment sit alongside a single packed Windows executable that carries every detection in the set — a pairing that reads less like a malware family and more like the internals of an ordinary software installer, repurposed. The image assets are unremarkable on inspection: a close button, a hover state, a grey button, a progress bar, a stylesheet named main.css. Individually they register 0/53 to 0/57 across antivirus engines.
#Snowglobe#AnimalFarm#Sig20#babarmalware#trojanizedinstaller#USretailsector#CloudFrontC2#packedexecutableActorsSnowglobe · Animal FarmIOCf18 · i0 · d2 · u0MITRE27RegionsUSIndustriesRetail
C&CMembersSep 11, 2026, 22:51 (UTC+9)Twenty Throwaway .xyz Domains Funnel Into One Kronos Panel Path
Twenty domains in this record — every one an algorithmically-generated string of consonant clusters under the .xyz top-level domain — resolve, wherever resolution data survives, to the identical checkout path /kronos/connect.php. That is not a coincidence of naming; it is the fingerprint of a single command-and-control panel template stamped across disposable infrastructure rather than the work product of twenty independent operators standing up their own C2.
#Kronosbankingtrojan#C2infrastructure#domaingenerationalgorithm#packed.NETloader#.xyzdomains#WHOISobfuscation#financiallymotivatedcybercrime#anti-analysistechniquesIOCf3 · i0 · d22 · u40MITRE31RegionsCH · JOIndustriesSupport Services
APTPublicSep 11, 2026, 22:38 (UTC+9)A Political Decoy Document Reopens a 2016 Word-Processor Flaw
A Korean-language document about inter-Korean political affairs is still being used to trigger a nine-year-old Hangul Word Processor flaw, and the payload it drops is evading a meaningful share of security engines nearly a decade after it was first compiled. The lure — a corrupted HWP container (29430240cb59a12fcde8e4153c0859c90d5a928503a1ca05433f08a7b3c50bf2) carrying an internal object path that resolves to a temp file named for a comparison of "2016 and 2017 South Korea-facing affairs" —…
#Group123#ScarCruft#APT37#ROKRAT#HWPexploit#CVE-2016-2569#SouthKorea#espionageActorsGroup123 · Venus 121IOCf2 · i1 · d0 · u0MITRE21RegionsCH · JOIndustriesSupport Services
C&CMembersSep 10, 2026, 22:28 (UTC+9)Shared Certificates Tie Decade-Spanning Domains to Proxyware Cluster
Five domains with nothing obviously in common — a fitness-therapy site, a Korean-registered shell, a martial-arts studio, a decade-old Chinese-registered parking page, and a fresh mobile subdomain — picked up new TLS leaf certificates from Google Trust Services within the same seven-week window in mid-2026. tswlmy.com has been registered since April 2013; fxlvpaiguan.com was registered on 2026-07-31, barely a month before the record was compiled.
#WireVPN#VPNMaster#BrightData#Zenlayer#proxyware#code-signingabuse#certificateprovisioning#PUAloadersActorsCactus · Cactus Ransomware GroupIOCf50 · i7 · d13 · u4MITRE12
FILEMembersSep 10, 2026, 14:52 (UTC+9)Fake Windows Update Binary Hides Stealc Credential Stealer
A binary that calls itself wsus.exe, complete with a spoofed "AdobeReaderFlash Corporation" copyright string, has been circulating disguised as a routine Windows Update helper — and underneath the generic trojan labels most antivirus engines assign it, a named detection rule identifies the payload specifically as Stealc, a known credential-stealing family.
#Stealc#masquerading#wsus.exe#sandboxevasion#HostkeyB.V.#credentialtheft#Silence#commandandcontrolActorsSilence · Contract CrewIOCf2 · i1 · d0 · u2MITRE23RegionsCH · CN · JOIndustriesSupport Services
C&CMembersSep 10, 2026, 14:43 (UTC+9)Amadey Malware Wears Expired Microsoft Certificate, Skips DNS
Two payloads dropped in the same late-July 2025 build window — a 2,582 KB Windows executable and a 6,338 KB 64-bit DLL — carry an identical Microsoft code-signing chain, down to the leaf certificate's serial number, and both fail signature verification the moment a scanner actually checks the math. The certificate reads "Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010," a fully-formed three-tier chain that would pass a glance at a properties…
#Amadey#RedLineStealer#LummaStealer#codesigningforgery#clipboardhijacking#C2infrastructure#commoditycrimeware#DNS-lessC2IOCf9 · i2 · d0 · u14MITRE43RegionsVN
C&CMembersSep 10, 2026, 06:48 (UTC+9)Shared Loader Code Links Five 'Unrelated' Malware Families to One C2
Ten files, five different antivirus family labels, and one code-level fingerprint that should not be there. A clipboard-hijacking banker compiled as a 251KB Windows executable and a bazaar-style loader shipped as a 109KB DLL — tools that vendor engines classify as entirely separate malware — both fire the identical YARA rule pair `INDICATOR_SUSPICIOUS_ReflectiveLoader and ReflectiveLoader.
#StealC#BazarLoader#ClipBanker#Amadey#reflectiveDLLinjection#bare-IPC2#AS214351#FemoITSolutionsIOCf10 · i3 · d0 · u8MITRE48
FILEMembersSep 9, 2026, 22:58 (UTC+9)Malware Sample Stalls to Dodge Sandboxes, Hides Behind Thin Infrastructure
A Windows executable masquerading as joduj.exe (e9e732f7…) sits idle after launch, deliberately stalling for long stretches and polling the CPU clock directly to work out whether it has landed inside a sandbox before it will do anything else. That single behavioural signature — confirmed by a malicious verdict from the Yomi Hunter sandbox and flagged by 55 of 75 engines — is the strongest piece of evidence in this case, and it maps cleanly to time-based sandbox evasion [T1497.003].
#SpringDragon#LotusBlossom#sandboxevasion#timestomping#importtableanalysis#SouthKorea#SKBroadband#espionagemalwareActorsSpring Dragon · Lotus BlossomIOCf5 · i2 · d0 · u4RegionsIN
C&CMembersSep 9, 2026, 22:36 (UTC+9)Valid Bright Data Certificate Signs a Sandboxed PBot Stealer
A residential-proxy SDK carrying a currently valid Bright Data Ltd code-signing certificate has been sandboxed with a malicious verdict naming the stealer family PBot — the freshest and most unsettling signal in a ten-file set that otherwise reads like ordinary VPN and proxy bloatware. Two other toolchains in the same batch ride certificates that have already been revoked or expired, yet neither produces a cleaner behavioural outcome than the one still in good standing.
#BrightDataSDK#PBotstealer#residentialproxyabuse#WEILAIGlobalSignEVcertificate#VPNMasterbundler#code-signingcertificateabuse#PUAadwareeconomy#trojanizedinstallerIOCf21 · i8 · d12 · u0MITRE21
APTMembersSep 9, 2026, 22:29 (UTC+9)Pirated Mortal Kombat Installer Feeds Debugger-Aware Loader Chain
Two unsigned Win32 installers dressed up as a pirated "Mortal Kombat 1" setup from the FitGirl repack scene are functioning as the entry point for a debugger-aware loader chain that ends with a second-stage payload fetched over plain HTTP. Both files carry identical product and copyright metadata — "Mortal Kombat 1" and "FitGirl" — and both use the meaningful name setup.exe, with one retaining the full internal path E:\Mortal_Kombat_1_--_fitgirl-repacks.site\setup.exe. Neither is code-signed.
#DBatLoader#DonutLoader#VoidArachne#SilverFox#piratedsoftwarelure#TLScertificatereuse#Russia-hostedinfrastructure#ingresstooltransferActorsVoid Arachne · Silver FoxIOCf9 · i5 · d2 · u1RegionsBR
C&CMembersSep 8, 2026, 22:31 (UTC+9)Fake Alibaba, UnionPay Certificates Mask C2 on China Mobile IPs
A TLS certificate now circulating across five carrier-grade Chinese IP addresses lists its subject organization as "Alibaba (China) Technology Co., Ltd." — a real corporate name borrowed for infrastructure that has nothing to do with the company. The certificate, serial 6696262f452fcf46b79266a8, carries the common name *.certfallback.com and was issued by GlobalSign's GCC R46 OV TLS CA 2025, an organization-validated authority that is supposed to confirm the entity behind a certificate before…
#Alibabaimpersonation#UnionPayimpersonation#ChinaMobile#TLScertificatespoofing#C2infrastructure#yunkeit.com#GlobalSignOVcertificate#carrierIPabuseIOCf3 · i6 · d3 · u1MITRE37
FILEPublicSep 8, 2026, 14:33 (UTC+9)Fake KMSPico Activator Cluster Traces to Adware Builder, Not APT10
A trojanized copy of KMSPico — the pirated-software crowd's favorite "free" Windows and Office activation tool — is the lure carrying an entire adware-bundler cluster: six installers and a companion batch script, all packaged inside Nullsoft Installer (NSIS) self-extracting archives and all first seen within a roughly nine-month window spanning April 2015 to January 2016.
#KMSPico#adwarebundler#NSISinstaller#code-signingcertificateabuse#browsefox#outbrowse#RedApolloAPT10misattribution#builder-as-a-serviceActorsRed Apollo · PotassiumIOCf7 · i1 · d1 · u0MITRE21RegionsJP