CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • APTPublicJun 29, 2026, 17:09 (UTC+9)

    TigerRAT's Five-Layer Anti-Analysis Stack Splits Sandbox Verdicts

    A 304-kilobyte Windows executable carrying a PE compile timestamp of October 24, 1998 — a date that predates the x86-64 processor architecture the binary actually requires to run — encapsulates the operational philosophy behind the latest TigerRAT sample tied to Silent Chollima (Andariel). The falsified timestamp is not the most sophisticated trick in the sample's arsenal, but it is the most emblematic: every layer of this implant has been deliberately engineered to mislead, delay, or defeat…

    #SilentChollima#Andariel#TigerRAT#custompacker#sandboxevasion#C2infrastructure#DPRKthreatactors#defenseandgovernmenttargeting
    ActorsSilent Chollima · AndarielIOCf1 · i1 · d0 · u1MITRE7
  • APTMembersJun 28, 2026, 17:04 (UTC+9)

    Emotet's Canadian Campaign Hides Behind Three-Layer Evasion Stack

    A 141-kilobyte Word document circulating in phishing email against Canadian targets carries more infrastructure engineering behind it than its modest file size suggests. The malicious document — an Emotet e2 epoch loader first submitted to VirusTotal on 15 October 2020 and still active in this campaign — sits at the front end of a three-layer hosting architecture that combines Cloudflare origin-masking, automated 89-day TLS certificate rotation, and a dedicated command-and-control node…

    #Emotet#TA542#MummySpider#Wordmacrodropper#PowerShelldownloader#compromisedWordPressinfrastructure#Canada#Cloudflareevasion
    ActorsEmotet Group · TA542IOCf3 · i1 · d3 · u5RegionsCA
  • APTMembersJun 28, 2026, 16:53 (UTC+9)

    Decade-Old German Domains Reactivated as Emotet C2 Backbone Targeting Philippines

    Six command-and-control domains now active in an Emotet campaign targeting the Philippines share a striking infrastructure characteristic: four of them were registered between 2005 and 2012 through a single German registrar, Cronon GmbH, and have been sitting dormant — or at least benign-facing — for years, accumulating the kind of domain-age legitimacy that reputation-based defences routinely reward with a pass.

    #Emotet#TA542#Philippines#CrononGmbH#domainaging#C2infrastructure#macromalware#credentialharvesting
    ActorsEmotet Group · TA542IOCf4 · i0 · d6 · u11RegionsPH
  • APTMembersJun 28, 2026, 01:25 (UTC+9)

    Shared Imphash Ties Four 'Different' Stealers to One Builder Stub

    Four Windows executables carrying four unrelated antivirus labels — AgentTesla, Bobik, "Reline," and an unnamed loader named pctool.exe — turn out to share the same import-table fingerprint, imphash f34d5f2d4577ed6d9ceec516c1f5a744, and the same PEiD packer signature. That single build lineage is the most durable and reproducible signal in an 18-file, 6-domain cluster CTX Team has been tracking: a commodity builder-and-stub layer that antivirus vendors are classifying as though it produced four…

    #RedlineStealer#AgentTesla#Bobik#Socelars#Fabookie#LazarusGroup#pay-per-installdistribution#imphashclustering
    ActorsLazarus Group · Hastati GroupIOCf18 · i3 · d6 · u17RegionsFR
  • APTPublicJun 27, 2026, 21:07 (UTC+9)

    Donot Team Hides Cryptominer Behind Tor C2 and Anti-VM Evasion

    A single 7,149-kilobyte Windows executable — packed, obfuscated, and deliberately named to impersonate a core Windows process — encapsulates one of the more analytically provocative payload configurations CTX Team has observed in a recent APTC-35 dataset. The binary, classified as trojan.dekimine and bearing the meaningful installation path %APPDATA%\pwo6\svchost.exe, does not merely steal data or open a remote shell.

    #APTC-35#DonotTeam#dekimine#cryptomining#TorC2#sandboxevasion#Poland#UPXpacking
    ActorsAPTC35 · Donot TeamIOCf58 · i1 · d0 · u0MITRE29RegionsPL
  • APTMembersJun 27, 2026, 16:55 (UTC+9)

    Seven Hostnames, One Timestamp: Mapping the yazanboss Dynamic-DNS Block

    Seven near-identical hostnames — 1yazanboss.no-ip.biz through 6yazanboss.no-ip.biz, plus a bare yazanboss.no-ip.biz — were all created at the exact same second, 2001-11-22T23:09:02Z, under a single Vitalwerks Internet Solutions, LLC / No-IP.com account, with matching admin and billing contacts listed out of Reno, Nevada on every WHOIS record.

    #yazanboss#DynamicDNS#No-IP.com#Sality#SaltySpider#USB-autorun#polymorphicpacker#retailsector
    ActorsSalty Spider · KuKuIOCf6 · i0 · d7 · u0MITRE49RegionsUSIndustriesRetail
  • APTMembersJun 26, 2026, 20:56 (UTC+9)

    APT29's 2013 MiniDuke Implant Still Beaconing via Aftermarket Domain in 2026

    Sixty-three of 76 antivirus engines correctly identify the 326-kilobyte Windows executable bearing SHA-256 05e4224d4dd4e5fbd381ed33edb5bf847fbc138fbe9f57cb7d1f8fc9fa9a382d as a MiniDuke Stage 3 trojan — yet one of only two sandboxes that processed it returned a 97-percent-confidence verdict of harmless. That split is not a data anomaly. It is the point.

    #APT29#MiniDuke#HongKong#sandboxevasion#C2infrastructure#espionage#aftermarketdomain#dynamicanalysisevasion
    ActorsAPT29 · MinidionisIOCf1 · i0 · d1 · u34MITRE12RegionsHK
  • APTMembersJun 26, 2026, 17:09 (UTC+9)

    Sims 4 Crack Installer Still Feeds Same CyberGate RAT

    Two unsigned Windows executables masquerading as pirated copies of "The Sims 4" — both stamped with the identical PE build timestamp of 2025-03-13, both traced through directory paths reading `setup_TS4.exe and setup_TS4.tmp — sit at the center of a small but instructive campaign that pairs a piracy lure with a fully evasion-aware RAT/keylogger payload. What makes this cluster notable isn't its scale; it's the discipline.

    #DustSquad#CyberGate#KeyloggerGeneric#Sims4crackinstaller#dynamicDNSC2#sandboxevasion#telecomsectortargeting#NSISdropper
    ActorsDustSquad · APTC34IOCf10 · i0 · d1 · u1MITRE35RegionsCH · ES · KR · PLIndustriesTelecommunications
  • APTPublicJun 26, 2026, 09:21 (UTC+9)

    Barium Hides Cobalt Strike Behind Spoofed BugSplat DLL and Expired Demo Certificate

    A 938-kilobyte ZIP archive circulating since late December 2024 carries one of the more deliberately layered evasion chains CTX Team has documented in recent months: a Cobalt Strike loader campaign attributed to Barium that deploys a spoofed BugSplat crash-reporter DLL, an opaque encoded second stage, active sandbox-detection logic, and a C2 node presenting an expired OpenSSL demo certificate with the common name set to 8.8.8.8 — Google's public DNS resolver.

    #Barium#CobaltStrike#DLLsideloading#TerndoorLoader#foodandbeveragesector#Jordan#OpenSSLdemocertificate#encodedpayload
    ActorsBarium · Wicked SpiderIOCf5 · i1 · d0 · u1RegionsJOIndustriesFood & Beverages
  • APTMembersJun 26, 2026, 01:23 (UTC+9)

    Decade-Old Keygen Trojan Anchors Multi-Stage Pakistan Espionage Chain

    Since CTX Team's earlier coverage of this operation, six new files have surfaced that materially deepen the picture of how the Godzilla Loader and PonyStealer campaign targeting Pakistan actually functions — not just what it delivers, but how it gets there. The new components introduce a second build cluster absent from prior analysis: a batch-script orchestrator, an invalid-signed SOCKS5 proxy tool, a PEiD-packed .NET spreader, and a delivery archive built around a keygen lure that has been…

    #GodzillaLoader#PonyStealer#Pakistanespionage#keygentrojan#SOCKS5proxy#credentialtheft#C2infrastructure#spreadermalware
    IOCf17 · i0 · d5 · u9MITRE34RegionsPK
  • APTMembersJun 25, 2026, 20:56 (UTC+9)

    EV Certificate Minted for One Campaign Powers Three-Layer Evasion Chain

    Thirty-nine days. That is the total operational window separating the moment a Sectigo Extended Validation certificate was issued to an entity called QUANTIS LOGIK LTD and the moment the two PE32 installers it signed first appeared on VirusTotal. The certificate — serial number 00 86 51 B4 B7 A5 AF 08 DF 82 E5 FE 4E 5B 99 A8 18, thumbprint 1080D4CCFE6E5EE372CB3DB8686C37923A932AF5, issued 2026-04-22, used to sign both payloads on 2026-05-19, with the files submitted on 2026-06-01 — was not a…

    #LummaStealer#OfferCore#EVcertificateabuse#CloudFrontdomain-fronting#sandboxevasion#LazarusGroup#telecomsector#code-signingabuse
    ActorsLazarus Group · Hastati GroupIOCf2 · i0 · d1 · u0MITRE21RegionsCO · DE · EG · FRIndustriesAgriculture · Support Services · Telecommunications
  • APTPublicJun 24, 2026, 21:30 (UTC+9)

    TA505 Rockloader C2 Hits SE Asia Finance With Zero Detections

    Three command-and-control domains registered within five weeks of each other, scoring zero detections across 91 antivirus engines, with WHOIS identity fields uniformly padded with the same 16-character hex string — this is the operational signature CTX Team has mapped to a TA505-attributed rockloader campaign currently targeting financial-services organisations in Cambodia and Singapore.

    #TA505#rockloader#command-and-controlinfrastructure#financialservices#Cambodia#Singapore#DGA#WHOISobfuscation
    ActorsTA505 · Hive0065IOCf9 · i0 · d3 · u0MITRE32RegionsKH · SGIndustriesFinancial Services
  • APTMembersJun 24, 2026, 01:23 (UTC+9)

    Fake YCleanner App Delivers LummaStealer After Four-Month Build Campaign

    A Windows executable branded as a system-cleaning utility — product name "YCleanner," internal name YC.exe, version 1.3.2.5 — has been circulating as the delivery vehicle for a dual-purpose attack chain combining LummaStealer credential theft with XMRig cryptomining, targeting Romania. The campaign's most operationally distinctive feature is not the payload itself but the architecture surrounding it: an encrypted outer container that achieves a clean sweep of 0/77 antivirus detections at the…

    #BlueBottle#LummaStealer#XMRig#Romania#credentialtheft#cryptomining#fakesoftwarelure#Opera1er
    ActorsBlueBottle · Opera1erIOCf16 · i0 · d1 · u1RegionsRO
  • APTMembersJun 23, 2026, 00:58 (UTC+9)

    Trojanised Adobe Firefly Installer Runs Triple-Monetisation Kill Chain on Construction Firms

    Pirated creative software has long been a reliable vector for commodity malware, but a campaign CTX Team has been tracking shows how far that distribution model has matured. Two oversized Windows executables — both named FireflyAI.exe, one weighing 45 MB and the other 53 MB — are circulating as trojanised installers for Adobe's Firefly AI tool, with one sample's embedded path string explicitly referencing "Firefly AI 25.0.0.2265 beta for Adobe Photoshop 24.7 (x64)." The lure has been active…

    #PureLogs#WinRing0BYOVD#Nanopool#trojanisedinstaller#constructionsector#credentialtheft#crypto-mining#C2infrastructure
    ActorsAPT28 · StrontiumIOCf21 · i4 · d5 · u4RegionsBR · DE · LUIndustriesConstruction
  • APTMembersJun 21, 2026, 16:13 (UTC+9)

    Emotet Hijacks Aged German Sites to Evade Detection in PNG Campaign

    Four German-hosted websites — three of them registered between 2000 and 2009, all of them delegating DNS through the same Cronon/Strato nameserver infrastructure — are serving as the distribution backbone for an active Emotet campaign targeting the hospitality sector in Papua New Guinea. The cluster, observed by CTX Team between 14 and 21 June 2026, is analytically notable not for the malware it delivers but for the hosting architecture it exploits: rather than spinning up fresh…

    #Emotet#TA542#CrononGmbH#rzone.de#hospitalitysector#PapuaNewGuinea#compromisedlegitimatedomains#PowerShelldownloader
    ActorsEmotet Group · TA542IOCf4 · i1 · d4 · u8RegionsPGIndustriesHospitality & Leisure
  • APTMembersJun 21, 2026, 04:00 (UTC+9)

    Kimsuky Hides Trojan in Npcap Installer With Valid Nmap Certificate

    A Nullsoft NSIS self-extracting installer bearing the filename npcap-1.88-oem-usnavy-testcopy-poexcu.exe — signed with a fully valid Nmap Software LLC code-signing certificate and scoring zero detections across 76 antivirus engines — represents one of the more deliberate evasion constructions CTX Team has documented in recent months.

    #Kimsuky#GuLoader#Npcap#code-signingabuse#driver-storemasquerading#defencesector#sandboxevasion#Authenticodeoverlay
    ActorsKimsuky · Velvet ChollimaIOCf33 · i0 · d0 · u0MITRE44
  • APTMembersJun 20, 2026, 16:10 (UTC+9)

    APT28 Hides Trojan in Pirated Software, Spreads via USB Across 22 Countries

    A 2,967-kilobyte Windows executable dressed up as "FL Studio 2025 Full Version.exe" is circulating across manufacturing and telecom networks in 22 countries, carrying a layered evasion stack that defeated one of three automated sandboxes outright — and the certificate stapled to it was issued the same day the file first appeared on VirusTotal, minted by a service that signs anything you give it.

    #APT28#trojan#USBspreader#piratedsoftwarelure#manufacturing#telecommunications#sandboxevasion#WMIexecution
    ActorsAPT28 · StrontiumIOCf1 · i1 · d3 · u3MITRE11RegionsAO · AR · AU · BOIndustriesManufacturing · Telecommunications
  • APTMembersJun 20, 2026, 15:58 (UTC+9)

    Snowglobe Adds Chrome-Extension Droppers, Leaves cheater.to Untouched

    Six new file indicators have joined the record CTX Team has been building around a Cloudflare-fronted domain called cheater.to — and none of them are new domains or IPs. That distribution alone is the story. The most consequential pair in the batch are two files that VirusTotal types as "Google Chrome Extension" containers, complete with the magic string "Google Chrome extension, version 3, XZ compressed, CRC64" — yet whose internal file paths resolve to ordinary Windows executables:…

    #Snowglobe#Babar#Vidarstealer#Salatstealer#masqueradingT1036#telecomespionage#cheater.to#Cloudflareinfrastructure
    ActorsSnowglobe · Animal FarmIOCf9 · i0 · d1 · u0MITRE43RegionsCZ · LT · SA · TRIndustriesTelecommunications
  • APTMembersJun 19, 2026, 03:56 (UTC+9)

    Spring Dragon Hides GCleaner in VR Installer With 4-Year-Old Certificate

    A Windows executable posing as an HTC VIVE Software installer has surfaced carrying a DigiCert code-signing certificate that expired in April 2021 — more than four years before the file appeared on any scanner — while beaconing to a trio of command-and-control domains registered, TLS-provisioned, and Cloudflare-proxied within a single 72-hour window.

    #SpringDragon#GCleaner#wmi_ghost#code-signingcertificateabuse#sandboxevasion#CloudflareC2proxying#HTCVIVElure#pay-per-installloader
    ActorsSpring Dragon · Lotus BlossomIOCf1 · i0 · d3 · u6MITRE12
  • APTPublicJun 18, 2026, 23:57 (UTC+9)

    Upatre Dropper Fires CryptoLocker Rules as Decade-Dormant Domain Wakes

    A 27-kilobyte Windows executable named case_10022013.exe sits at the centre of a delivery chain that has been quietly circulating since at least October 2013 — and the most analytically striking detail is not its age but its identity crisis. The binary is classified by 66 of 77 antivirus engines as Upatre, the compact downloader long associated with the Gold Evergreen / Business Club criminal ecosystem.

    #GoldEvergreen#BusinessClub#Upatre#CryptoLocker#ZBot#legal-lurephishing#long-dormantC2infrastructure#dual-familymalware
    ActorsGold Evergreen · Business ClubIOCf3 · i0 · d1 · u1MITRE9
  • APTMembersJun 18, 2026, 15:58 (UTC+9)

    Forged 72-Hour Certificates Hid WarzoneRAT From All 76 AV Engines

    Seven Windows executables and DLLs, all signed under the name of a legitimate German digital-publishing company, arrived on VirusTotal on 23 May 2026 with a combined static detection score of zero across 76 engines. The files presented themselves as components of "t-online Browser 7," a real product distributed by Ströer Digital Publishing GmbH — complete with version strings, Mozilla Public License 2.0 copyright notices, and Authenticode signatures rooted in Microsoft's own…

    #APT28#WarzoneRAT#Winos4.0#Skip-2.0#code-signingabuse#energysector#GermanyFranceLuxembourg#Authenticode
    ActorsAPT28 · StrontiumIOCf55 · i0 · d0 · u0MITRE55RegionsDE · FR · LUIndustriesEnergy · Technology · Telecommunications
  • APTMembersJun 18, 2026, 04:04 (UTC+9)

    NullMixer Bundle Drops Five Malware Families via Discord Fake Installer

    A single Windows executable masquerading as a software setup wizard unpacks at least five distinct malware families the moment a user double-clicks it — RedlineStealer, ClipBanker, SmokeLoader, StealBit, and Upatre arriving as a coordinated bundle rather than a sequential chain. That delivery model, confirmed by the Malpedia YARA rule win_nullmixer_auto firing on two large installer files and by unanimous sandbox verdicts naming four families simultaneously, is the operationally distinctive…

    #APT28#NullMixer#RedlineStealer#SmokeLoader#ClipBanker#DiscordCDNabuse#Bolivia#fakeinstaller
    ActorsAPT28 · StrontiumIOCf18 · i3 · d4 · u10RegionsBO
  • APTMembersJun 17, 2026, 23:57 (UTC+9)

    DHL-Lure RAR Delivers MassLogger to Construction Firms Across Four Countries

    A 946-kilobyte RAR archive named DHL_AWB#6078538091.rar has been circulating since mid-May 2026 as the opening move in a credential-harvesting campaign targeting construction-sector organisations across Germany, India, Malaysia, and Turkey. The archive is not simply a container — it is itself the first evasion layer, carrying explicit debugger-detection and long-sleep logic that caused one major automated analysis platform to return a clean verdict at 96% confidence while a second correctly…

    #APT29#MassLogger#Formbook#credentialharvesting#constructionsector#sandboxevasion#spear-phishing#processinjection
    ActorsAPT29 · MinidionisIOCf3 · i0 · d0 · u0MITRE23RegionsDE · IN · MY · TRIndustriesConstruction
  • APTMembersJun 17, 2026, 20:00 (UTC+9)

    Salat Stealer Bypasses Chrome v127 Encryption in Capability Leap

    A 12-megabyte unsigned Windows executable first observed on 2 May 2026 carries a capability set that goes well beyond what commodity stealers typically offer: a working Chromium app-bound encryption decrypter, a large embedded catalogue of cryptocurrency wallet browser-extension identifiers, and a command-and-control resolution path routed through Cloudflare's DNS-over-HTTPS service to defeat the DNS-layer monitoring that would otherwise expose its infrastructure.

    #SalatStealer#Chromiumapp-boundencryptionbypass#DNS-over-HTTPSevasion#credentialtheft#cryptocurrencywalletharvesting#APT28#CloudflareCDNabuse#browsercredentialstores
    ActorsAPT28 · StrontiumIOCf1 · i2 · d3 · u2MITRE11
  • APTMembersJun 17, 2026, 13:49 (UTC+9)

    APT10's 2016 ChChes Implant Runs on C2 Renewed in 2025

    A 283-kilobyte Windows executable compiled in November 2016 carries a code-signing certificate that expired more than a decade ago — yet the command-and-control domain it phones home to received a fresh TLS certificate as recently as September 2025. That tension between aged tooling and actively maintained infrastructure is the defining characteristic of a ChChes implant attributed to Red Apollo (APT10) that CTX Team has been tracking since December 2024.

    #RedApollo#APT10#ChChes#OperationCloudHopper#code-signingabuse#C2infrastructure#sandboxevasion#espionage
    ActorsRed Apollo · PotassiumIOCf1 · i0 · d1 · u5MITRE13
  • APTMembersJun 17, 2026, 13:31 (UTC+9)

    Scripted CKEditor Exploitation Endpoints Surface Across Two Campaign Domains

    Four newly documented URLs targeting the CKEditor-for-WordPress plugin across two domains — kartacnictvi.cz and mokawafm.com — now explicitly expose the scripted initial-access mechanism behind a campaign CTX Team has been tracking in connection with a Lazarus Group CRAT implant. Each URL follows the same path structure — wp-content/plugins/ckeditor-for-wordpress/ckeditor/plugins/image/ — and carries a hex-timestamp query parameter: ts=6A4310F7_1897026C, ts=6A431118_12AB12AC,…

    #LazarusGroup#CRAT#Nukesped#Zusy#WordPressCKEditor#Jordan#foodandbeverages#initialaccess
    ActorsLazarus Group · Hastati GroupIOCf2 · i2 · d2 · u6MITRE19RegionsJOIndustriesFood & Beverages
  • APTMembersJun 17, 2026, 10:08 (UTC+9)

    TA505 Fake Purchase Order Hides JS Payload 70 Engines Cannot See

    A spear-phishing campaign attributed to TA505 is circulating a Varist-packed RAR archive named after a fake purchase order — but the real detection problem sits one extraction step deeper: the JavaScript payload inside evades 70 of 76 antivirus engines despite both sandboxes that processed it returning unambiguous malicious verdicts, and despite an Abuse.ch IDS rule already flagging its PureHVNC command-and-control certificate.

    #TA505#PureHVNC#JavaScriptdropper#spear-phishing#procurementsector#sandboxevasion#Unicodeobfuscation#dormantdomainreactivation
    ActorsTA505 · Hive0065IOCf2 · i0 · d1 · u2RegionsCY · DE · DK · FRIndustriesRetail · Support Services · Technology
  • APTMembersJun 17, 2026, 09:42 (UTC+9)

    XWorm V5.6 Deploys 18-Plugin Suite Behind Azure-Hosted C2 Fleet

    A complete, operationally ready XWorm V5.6 toolkit — nineteen files in total, comprising a main RAT executable and eighteen purpose-built plugin DLLs compiled from a single build pipeline — has been observed in active deployment, with the plugin suite spanning hidden VNC access, keylogging, browser credential theft, ransomware, CMSTP-based UAC bypass, and Windows Defender suppression.

    #GamaredonGroup#XWorm#HiddenTearransomware#HVNC#CMSTPUACbypass#credentialharvesting#Azureinfrastructureabuse#Ukraine
    ActorsGamaredon Group · CTIGIOCf43 · i0 · d9 · u18MITRE37RegionsBD · DE · GB · IN
  • APTMembersJun 15, 2026, 10:27 (UTC+9)

    BlueBottle Hides Cryptominer in Fake FileZilla Update Targeting DRC

    A typosquatted domain impersonating the FileZilla FTP client is serving a two-stage dropper-binder chain to targets in the Democratic Republic of Congo — an operation that pairs brand-impersonation lures with layered sandbox evasion baked into every executable stage, while beaconing to the hashvault.pro cryptomining pool over a CoinMiner JA3 TLS fingerprint.

    #BlueBottle#Opera1er#BitRAT#cryptomining#DemocraticRepublicofCongo#typosquatting#sandboxevasion#FileZillaimpersonation
    ActorsBlueBottle · Opera1erIOCf4 · i1 · d1 · u2MITRE18RegionsCD
  • APTMembersJun 15, 2026, 10:15 (UTC+9)

    TA511 Bundle Deploys StealC v2 With Chrome Encryption Bypass via Single German AS

    ##A Four-Family Payload Bundle Targets Browser Credentials and Crypto Wallets From a Single German Hosting Fabric A coordinated malware campaign deploying Amadey, StealC v2, LummaC2, and ClipBanker as a unified payload bundle has concentrated every observed command-and-control endpoint inside a single autonomous system — AS214351, operated by Femo It Solutions Limited — a RIPE NCC-registered provider that came into existence in October 2024 and whose IP space spans just two /24 subnets…

    #TA511#StealCv2#Amadey#ClipBanker#AS214351#Chromiumapp-boundencryptionbypass#credentialtheft#cryptocurrencyhijacking
    ActorsTA511 · MAN1IOCf33 · i3 · d0 · u6RegionsCLIndustriesTechnology
  • APTMembersJun 14, 2026, 22:29 (UTC+9)

    KMSpico Campaign Adds 9 Variants, Core Four-Layer Evasion Stack Unchanged

    Nine new file indicators have surfaced in the Molerats-attributed KMSpico campaign since CTX Team's earlier coverage, expanding the known file set to 17 samples — yet not a single new network indicator has emerged alongside them. The delta is entirely on the file side, and the pattern shows an operator iterating the outer delivery shell while leaving the campaign's most distinctive technical architecture completely intact: a four-layer evasion stack built around a self-issued certificate…

    #Molerats#KMSpico#Formbook#WinDivert#Dotfuscator#code-signingabuse#technologysector#Malaysia
    ActorsMolerats · Gaza CybergangIOCf17 · i0 · d0 · u0MITRE19RegionsMYIndustriesTechnology
  • APTMembersJun 14, 2026, 10:17 (UTC+9)

    APT27's Godzilla Loader Factory: 18 Cloned Binaries, One C2 Gate

    Nineteen PE32 executables. One YARA rule. Six .ru domains. A single PHP gate path with a campaign identifier that never changes. What CTX Team's analysis of this cluster reveals is not a hastily assembled intrusion kit but the output of a production-grade payload generation pipeline — one where 18 structurally identical 9 KB binaries are stamped from a single build toolchain, each mutated just enough at the byte level to carry a distinct fuzzy hash while preserving an identical PE import table,…

    #APT27#GodzillaLoader#PonyStealer#certificateabuse#C2infrastructure#Italy#payloadfactory#code-signingabuse
    ActorsAPT27 · TEMP.HippoIOCf28 · i0 · d24 · u12MITRE9RegionsIT
  • APTMembersJun 14, 2026, 06:29 (UTC+9)

    One Fake Certificate Signs 13 Pirated Windows Activation Tools

    Thirteen Windows binaries marketed under a dozen different brand names — AAct, KMSAuto Net, MSAct++, PIDKey Lite, KMSCleaner — all carry the identical self-issued code-signing certificate from an entity calling itself "WZTeam," serial E5 FA 25 47 0F 85 17 BF 41 52 87 01 4D AA 57 8C, thumbprint 87B3A6C360B37D6DB7F970DD1DC0009FBBD13BA0.

    #APT27attributionmismatch#crack-toolecosystem#KMSAutoKMSpicoAAct#code-signingcertificateabuse#Formbookanti-hookYARA#WindowsDefenderbypass#piratedsoftwaresupplychain#hacktoolPUAclassification
    ActorsAPT27 · TEMP.HippoIOCf51 · i0 · d0 · u0MITRE37RegionsHR · IN · PL · SIIndustriesEducation & Research · Hospitality & Leisure
  • APTMembersJun 14, 2026, 02:27 (UTC+9)

    Dormant Domain Reactivated With Fresh Cert to Power Backdoor C2

    A domain registered in December 2019 and left parked behind ad-network nameservers for more than six years quietly received a new, short-lived TLS certificate on September 1, 2025 — and within weeks was hosting a live-looking command-and-control subdomain. The domain, wthelpdesk.com, is the single richest piece of evidence in this record, and it tells a story less about a specific actor than about how patiently some operators are willing to season their infrastructure before switching it on.

    #RedApollo#APT10#ChChes#CloudHopper#domainparking#Let'sEncryptcertificateabuse#backdoormalware#XORobfuscation
    ActorsRed Apollo · PotassiumIOCf1 · i0 · d1 · u5RegionsDE
  • APTMembersJun 14, 2026, 02:14 (UTC+9)

    Fake KMS Activators Share One Untrusted Signing Certificate

    Two Windows executables masquerading as pirated-software tools — one branded "KMSAuto++.exe," the other disguised as an "Office 2013-2021 C2R Install Lite" installer — are circulating with an identical, untrusted code-signing certificate stamped by an entity calling itself WZTeam. The certificate, serial 8A C1 A3 10 13 49 C2 8A 4D 33 94 7C FC D0 76 62, terminates in a root that Windows does not trust, yet it appears verbatim across both binaries, alongside a shared VirusTotal family label of…

    #KMSAuto#code-signingcertificateabuse#UPXpacking#PowerShelldownloader#piratedsoftwaredistribution#APT27#njRAT#maliciousdomaininfrastructure
    ActorsAPT27 · TEMP.HippoIOCf16 · i0 · d2 · u2MITRE53RegionsTHIndustriesTelecommunications
  • APTMembersJun 13, 2026, 02:32 (UTC+9)

    WHQL-Signed Kernel Driver With 2/76 Detections Opens Stealc v2 Kill Chain

    A 34-kilobyte Windows kernel driver signed by the Microsoft Windows Hardware Compatibility Publisher — carrying a WHQL certificate chain that traces back to Microsoft's own root authority — is being deployed as the opening move in a five-stage financial-theft campaign that ultimately delivers Stealc v2 credential stealers capable of bypassing Chromium app-bound encryption and in-process clipboard hijackers targeting cryptocurrency wallet addresses.

    #WizardSpider#Stealcv2#BYOVD#Amadey#clipboardhijacker#Chromiumapp-boundencryption#AS214351#kerneldriverabuse
    ActorsWizard Spider · Grim SpiderIOCf11 · i3 · d1 · u5MITRE71RegionsAR · DE · IN · NG
  • APTMembersJun 12, 2026, 06:42 (UTC+9)

    Emotet OCX Loader Beacons to Four Continents via regsvr32 Proxy

    A 64-bit Windows DLL masquerading as an OLE Control Extension file — delivered under the name hvxda.ocx and designed to run through regsvr32 rather than a conventional executable launcher — sits at the centre of an active Emotet deployment that has been beaconing to four geographically dispersed command-and-control servers across Malaysia, Ghana, Germany, and South Korea.

    #Emotet#TA542#Dridex#regsvr32proxyexecution#multi-epochC2infrastructure#bankingtrojan#GeorgiaandQatartargeting#FeodoTracker
    ActorsEmotet Group · TA542IOCf1 · i4 · d0 · u7MITRE21RegionsGE · QA
  • APTMembersJun 11, 2026, 14:40 (UTC+9)

    Same-Day Certificates Expose Scripted C2 Build-Out Behind Two Trojans

    Three infrastructure nodes — the IPs 31.58.134.74 and 80.97.160.31, plus the freshly minted domain powershell-storage.vg — received Let's Encrypt certificates from the same "YE2" intermediate within a two-day window in June, each carrying an identical 89-day validity span. That kind of synchronized issuance is not how organically managed hosting behaves; it is what scripted infrastructure provisioning looks like when an operator wants a C2 front live and disposable within hours of registering…

    #APT28#NICENIC#Let'sEncryptcertificates#DNSPod#C2infrastructure#codesigningabuse#installertrojans#domainregistrationcluster
    ActorsAPT28 · StrontiumIOCf7 · i4 · d5 · u6RegionsID · MY · PL
  • APTPublicJun 11, 2026, 14:25 (UTC+9)

    Shell Crew's Zero-Detection C2 and Anti-Forensic Toolkit Hit Mexico Construction

    Five hacktools attributed to Shell Crew — the Chinese state-aligned intrusion set also tracked as Deep Panda, APT26, Turbine Panda, and Checkered Typhoon — have been linked to an active espionage campaign targeting Mexico's construction sector, with a command-and-control node on China Unicom's commercial backbone that registered zero detections across 91 VirusTotal engines despite carrying a named-actor attribution.

    #ShellCrew#DeepPanda#terracotta_vpn#Mexicoconstructionsector#ChinaUnicomAS-4837#anti-forensictradecraft#credentialdumping#C2infrastructure
    ActorsShell Crew · WebMastersIOCf5 · i1 · d0 · u0MITRE28RegionsMXIndustriesConstruction
  • APTMembersJun 10, 2026, 10:17 (UTC+9)

    Emotet DLL Poses as Chinese AV, Beacons to Five-ASN C2 Pool

    A 572-kilobyte Windows DLL is circulating across healthcare networks in Panama wearing the identity of a Chinese-language antivirus product — its PE version-info fields stamped with the product name "MJAntiVirus.EXE," an internal name of "MJAntiVirus," and a copyright string reading "版权所有 (C) 2009." The file is unsigned, packed with PEiD, and carries a .rsrc section registering entropy at 7.75. It is, by unanimous verdict of six independent sandboxes, Emotet.

    #Emotet#Dridex#TA542#healthcaresector#Panama#C2infrastructure#TLSfingerprinting#PEmasquerading
    ActorsEmotet Group · TA542IOCf1 · i5 · d0 · u9MITRE26RegionsPAIndustriesHealthcare
  • APTMembersJun 10, 2026, 06:38 (UTC+9)

    One Expired Microsoft Cert Ties Three Amadey Dropper Stages Together

    Five Windows executables — two trojanised KMS software-activation tools, two dedicated AV-killing binaries, and a fully operational Amadey bot loader — form a tightly bound dropper chain whose most distinctive feature is not the payload at the end but the build discipline that assembles it. A single expired Microsoft Windows Publisher leaf certificate, serial 33 00 00 02 4B B2 23 0A 43 CD 03 63 62 00 00 00 00 02 4B, has been stamped across three distinct malware stages with an identical signing…

    #Amadey#KillAV#PS2EXE#KMSlure#certificateabuse#piracydistribution#RussiaC2infrastructure#dropperchain
    IOCf9 · i1 · d0 · u3MITRE31RegionsZW
  • APTMembersJun 9, 2026, 23:05 (UTC+9)

    APT28-Linked Loader Fires Amadey Signatures Despite DCRat Tag

    A single Win32 executable now under continued watch by CTX Team carries three contradictory identities at once: the feed classifies it under the DCRat family, VirusTotal's own engines settle on the threat label "trojan.abmrisk/common," and the network traffic it generates fires Snort signatures written specifically for Amadey.

    #APT28#Amadey#DCRat#loadermalware#commandandcontrol#Pleskauto-certificate#OmegatechLTD#codesigningevasion
    ActorsAPT28 · StrontiumIOCf2 · i1 · d0 · u1MITRE25RegionsBD · BF · BR · DZIndustriesTechnology
  • APTMembersJun 9, 2026, 11:38 (UTC+9)

    IPFS Gateway Joins APT28-Linked C2 Stack Spanning Three Autonomous Systems

    Two new IP addresses have been added to the infrastructure footprint of a delivery campaign that has been circulating trojanised installers and adware components since at least September 2025 — and one of them points somewhere unusual. IP 209.94.90.1, now part of the campaign's network layer, sits within ASN 40680, the address space operated by Protocol Labs, the organisation behind the InterPlanetary File System.

    #APT28#IPFSabuse#PremierOpinionadware#code-signingcertificateabuse#DLLsideloading#technologysectortargeting#bulletproofhosting#trojanisedinstallers
    ActorsAPT28 · StrontiumIOCf4 · i3 · d4 · u0MITRE13IndustriesTechnology
  • APTMembersJun 9, 2026, 07:24 (UTC+9)

    Void Arachne Hides DBatLoader Inside Fake FitGirl Game Repack Targeting Brazil

    Two unsigned PE32 executables — both carrying the version metadata "product: 007 First Light / copyright: FitGirl" — have been circulating through pirated-software distribution channels targeting Brazilian users, wrapped inside a structurally complete fake game repack that bundles a Play.bat launcher, a game cover image, a convincing uninstaller, and a counterfeit DirectX installer to defeat automated sandbox analysis.

    #VoidArachne#DBatLoader#Banload#Brazil#gamerepacklure#sandboxevasion#Russianhostinginfrastructure#initialaccesstrojan
    ActorsVoid Arachne · Silver FoxIOCf17 · i4 · d2 · u0RegionsBR
  • APTMembersJun 8, 2026, 23:36 (UTC+9)

    Signed FileZilla Installer Hides Adware Bundler Behind Valid Sectigo Chain

    A file calling itself FileZilla_3.69.5_win32-setup.exe is circulating with a complete, currently-valid Sectigo code-signing chain — Tim Kosse through Sectigo Public Code Signing CA R36, Sectigo Public Code Signing Root R46, and the Sectigo (AAA) root — even as 12 of 75 antivirus engines classify it as adware.bundler/filezilla.

    #FileZilla#adwarebundler#code-signingabuse#Sectigocertificate#NSISinstaller#APT28#APT15#threatintelmisattribution
    ActorsAPT28 · StrontiumIOCf1 · i4 · d1 · u1MITRE9IndustriesEducation & Research
  • APTMembersJun 8, 2026, 23:07 (UTC+9)

    Lazarus Group Hides LummaC2 Stealer Behind Signed Installer and AWS CDN

    Four indicators. Two signed Windows executables. Two AWS CloudFront subdomains that score zero detections across 91 engines. In practice, a delivery architecture that defeats network-layer blocking, suppresses antivirus verdicts on the second-stage payload to 4 out of 77 engines, and defeats dynamic analysis entirely — all simultaneously, all through infrastructure that any enterprise legitimately uses every day.

    #LazarusGroup#LummaC2#code-signingabuse#AWSCloudFront#sandboxevasion#financialservices#trojanizedinstaller#informationstealer
    ActorsLazarus Group · Hastati GroupIOCf2 · i0 · d2 · u0MITRE21RegionsAE · BR · FR · LYIndustriesFinancial Services
  • APTMembersJun 8, 2026, 15:09 (UTC+9)

    Salty Spider Abuses Live DigiCert Cert for 17 Months of Malicious Builds

    Seven Windows executables and DLLs flagged as adware — spanning two distinct 2345 Software product lines — carry an identical, currently-valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd., and the operator was still applying that same credential to fresh malicious builds as recently as April 7, 2026.

    #SaltySpider#2345Software#code-signingabuse#adware#AlibabaCDN#China#T1553.002#softwaresupplychain
    ActorsSalty Spider · KuKuIOCf15 · i16 · d2 · u2MITRE16
  • APTMembersJun 7, 2026, 23:21 (UTC+9)

    DarkHotel's Decade-Old Nemim Trojan Still Evades Detection in 2026

    A 56-kilobyte Windows executable first submitted to VirusTotal in February 2013 is still being resubmitted and tracked as an active threat as recently as March 2025 — and the infrastructure supporting it has grown fresher, not older. The implant at the centre of this campaign is Nemim, a multi-role trojan attributed by CTX Team to DarkHotel and directed at espionage targets in India.

    #DarkHotel#Nemim#dynamic-DNS#India#espionage#sandboxevasion#commandandcontrol#APT
    ActorsDarkHotel · Fallout TeamIOCf2 · i1 · d0 · u9MITRE28RegionsIN
  • APTMembersJun 7, 2026, 23:07 (UTC+9)

    BlueBottle's FileZilla Impersonation Campaign Hides XMRig Behind Zero-Detection ZIP

    A PE32 dropper bearing a self-signed "FileZilla FTP Client" code-signing certificate — its validity start date of 2025-12-24 matching, to the day, the registration date of the campaign's C2 domain filezilla.cc — sits at the centre of a multi-stage XMRig cryptominer delivery chain that CTX Team has tracked from January through June 2026.

    #BlueBottle#Opera1er#XMRig#cryptominer#DemocraticRepublicofCongo#code-signingabuse#encrypteddeliverycontainer#Cloudflarefronting
    ActorsBlueBottle · Opera1erIOCf19 · i1 · d1 · u2MITRE29RegionsCD
  • APTMembersJun 7, 2026, 07:20 (UTC+9)

    Fake Synaptics Driver Rebuilt for Three Years, Now a Confirmed RAT

    Three unsigned Win32 loaders — the oldest first appearing in December 2020, the newest surfacing in November 2023 — share one imphash, an identical PE section layout down to the byte, and a forged compile timestamp of 1992-06-19 that predates Windows 95. All three carry the same fake product string, "Synaptics Pointing Device Driver," version 1.0.0.4, and two of them drop to the identical path, C:\ProgramData\Synaptics\Synaptics.exe.

    #Synapticsdrivermasquerade#DarkKomet#XRed#XWorm#imphashreuse#certificatefronting#dynamicDNSabuse#IndraPredatorySparrow
    ActorsIndra · Predatory SparrowIOCf13 · i5 · d0 · u0RegionsEC
2
Of4
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.