APTMembersJun 6, 2026, 23:10 (UTC+9)Ludashi Adware Ring Abused DigiCert Certs Across Five Shell Firms
Fifteen signed Windows executables. Five distinct Chinese company identities. One commercial certificate authority. A single cert serial binding nine of those payloads to a three-year production window that is still running. The operation CTX Team has been tracking targets the telecom sector and exploits a structural weakness that most enterprise endpoint stacks have not solved: when a binary carries a valid, trusted code-signing certificate, a significant fraction of the detection stack simply…
#Ludashi#DigiCertcertificateabuse#code-signingevasion#adware#TencentCloudinfrastructure#telecommunicationssector#overlayhashmutation#certificaterevocationfailureActorsGorgon Group · SubaatIOCf29 · i22 · d4 · u0MITRE10IndustriesTelecommunications
APTMembersJun 6, 2026, 19:24 (UTC+9)Expired and Revoked Certs Anchor Active Malware Delivery Chain
Three Windows executables are circulating through software download channels carrying code-signing certificates that, by any standard enforcement logic, should stop them cold. One bears a DigiCert leaf certificate for an entity called VOICEFIVE, INC that expired on 3 April 2026. The other carries a Certum Extended Validation certificate for "AN Soft" that has been explicitly revoked.
#APT28#surtr#certificateabuse#code-signing#PremierOpinion#sandboxevasion#technologysector#supplychaindeliveryActorsAPT28 · StrontiumIOCf4 · i5 · d5 · u0MITRE7IndustriesTechnology
APTMembersJun 6, 2026, 11:07 (UTC+9)Three Shell Companies, One Pipeline: Chinese Signing Op Delivers PubNubRAT
Sixteen malicious Windows executables and DLLs are currently circulating under valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 certificates — each certificate issued to a distinct Chinese-registered legal entity, each carrying a three-year validity window, and each actively suppressing the dynamic analysis environments that defenders rely on to catch what static signatures miss. The operation is not a single rogue certificate.
#PubNubRAT#Ludashi#Chinad#code-signingabuse#China-nexus#DigiCert#AS4837#supplychaindeliveryActorsFIN6 · Skeleton SpiderIOCf40 · i5 · d3 · u1MITRE18
APTMembersJun 6, 2026, 03:06 (UTC+9)Expired C2 Domain Closes Loop on Red Apollo KMSPico Adware Campaign
A single domain registered in October 2017 — idyllicdownload.com, acquired through Silver Domain Names LLC and abandoned within a year — has emerged as the confirmed network checkin endpoint for a pair of NSIS-packaged OutBrowse adware installers that masquerade as the KMSPico Windows activation crack. The domain's addition to the indicator catalog closes the delivery-to-C2 loop on a campaign attributed to Red Apollo, the China-aligned threat actor also tracked under the aliases APT10,…
#RedApollo#APT10#OutBrowse#NSISinstaller#KMSPicolure#Germanmanufacturing#C2infrastructure#adwarecampaignActorsRed Apollo · PotassiumIOCf6 · i0 · d1 · u2MITRE38RegionsDEIndustriesManufacturing
APTMembersJun 5, 2026, 23:19 (UTC+9)Fake ChatGPT Installer Hides Proxy SDK Classified as PBot Stealer
When a user downloads what appears to be a Windows client for ChatGPT from chatgpt-windows.top — a domain registered on 2025-06-03 and already flagging 13 of 91 engines on VirusTotal — they receive something considerably more complex than a VPN application. CTX Team's analysis of this campaign reveals a layered abuse chain in which trojanized VPN installers branded as WireVPN and VPNMaster silently co-install a Dotfuscator-obfuscated .NET component signed by Bright Data Ltd that two independent…
#PBotstealer#WireVPN#VPNMaster#BrightDataSDK#expiredEVcertificates#residentialproxyabuse#softwarebundlingsupplychain#AI-lurephishingActorsSpace Pirates · WebwormIOCf51 · i33 · d76 · u14MITRE20
APTMembersJun 5, 2026, 07:37 (UTC+9)Three Chinese Shell Firms, One DigiCert Chain, and a Kernel Driver in an Adware Campaign
Fourteen months of continuous payload production. Eleven distinct PE files — DLLs and installer EXEs alike — all bearing the same unrevoked leaf certificate issued to a single Beijing-registered technology company. A second Chinese entity in Chengdu holding its own valid DigiCert credential, and a third Chengdu firm with a third.
#SaltySpider#BYOVD#WinRing0#code-signingabuse#PUAadware#China#DigiCertcertificatechain#CDNfrontingActorsSalty Spider · KuKuIOCf37 · i12 · d3 · u3MITRE32
APTMembersJun 4, 2026, 23:26 (UTC+9)CapableWin Adware Suite Signed in Nine Minutes, Certificate Still Live
Seven Windows executables branded as "CapableWin" — a Chinese-language PC utility marketed as 全能电脑助手, or "All-in-One PC Assistant" — were compiled, versioned, and signed within a nine-minute window on the morning of 8 September 2025, all carrying a currently-valid GlobalSign code-signing certificate issued to Beijing entity 北京华网智讯软件有限公司 that remains unrevoked despite detection rates reaching 39 of 77 engines across the suite.
#MustangPanda#SoftCnApp#IcedID#code-signingabuse#CDNtrafficblending#Chineseadwareecosystem#PEoverlayconcealment#WindowsendpointActorsMustang Panda · HoneyMyteIOCf7 · i27 · d0 · u0
APTMembersJun 4, 2026, 23:13 (UTC+9)19 Trojanized IME Files Share One DigiCert Cert, Route C2 Through China's Largest CDN
##One Certificate, Nineteen Payloads: How a Wubi IME Trojan Hides Behind a Valid DigiCert Signature and China's Largest CDN Nineteen Windows executables — all masquerading as the 万能五笔输入法 (WanNeng Wubi IME) Chinese input-method suite and all carrying a single valid DigiCert code-signing certificate issued to Shanghai Oriental Webcasting Co. Ltd.
#SaltySpider#SoftCNApp#Burden#Fragtor#code-signingabuse#CDNinfrastructureblending#ChineseIMEmasquerade#ICMPreconnaissanceActorsSalty Spider · KuKuIOCf23 · i10 · d0 · u0MITRE10
APTMembersJun 4, 2026, 19:21 (UTC+9)APT28 Hides RAT Stack Inside Trojanised Deepfake AI Tool
A 43-megabyte Windows executable named Deep-Live-Cam-VFX.exe — convincingly dressed as a popular open-source deepfake application — has been circulating across at least nine independent submission sources, carrying inside it a PyInstaller-packed payload cluster that drops VenomRAT, a clipboard hijacker, and a browser credential stealer onto victim machines.
#APT28#VenomRAT#njRAT#LummaStealer#deepfakelure#VietnamC2infrastructure#credentialharvesting#cryptocurrencywallettheftActorsAPT28 · StrontiumIOCf9 · i0 · d3 · u3MITRE53RegionsNL · TR
APTMembersJun 4, 2026, 07:09 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Espionage Campaign Across Five Nations
A cryptominer, a clipboard hijacker, a reflective-loading stealer, and a Bring-Your-Own-Vulnerable-Driver instrument built from a kernel module first compiled in 2008 — this is the toolkit CTX Team has been tracking across targets in Brazil, India, Lithuania, Mexico, and Romania since late April 2026. The campaign's most operationally distinctive feature is not any single payload but the deliberate pairing of freshly compiled 2026-era commodity stealers with WinRing0x64.sys (sha256:…
#BYOVD#WinRing0x64#Vidarstealer#Salatstealer#clipboardhijacker#cryptominer#Lithuania#AezaGroupAS210644ActorsAPT28 · StrontiumIOCf22 · i2 · d0 · u4MITRE61RegionsBR · IN · LT · MX
APTMembersJun 3, 2026, 19:10 (UTC+9)13 Trojanized Updates, Two Live Certs: Inside a Chinese CDN Signing Abuse Campaign
Thirteen malicious Windows executables bearing valid, unrevoked Authenticode signatures from two separate Chinese software vendors have been circulating inside the update pipelines of widely-installed consumer applications — a signed-binary abuse chain [T1553.002] that walks past Authenticode-based endpoint defences on every build produced across a six-month window.
#signedbinaryabuse#Authenticode#Chinadadware#Rhadamanthys#supplychaincompromise#Chineseconsumersoftware#CDNdelivery#Skip-2.0ActorsAPT28 · StrontiumIOCf28 · i26 · d2 · u6MITRE11
APTMembersJun 3, 2026, 12:23 (UTC+9)APT29 Deploys Four-Layer Browser Fingerprinting in Energy-Sector Spearphish
A spearphishing operation targeting energy-sector organisations has surfaced carrying an unusually disciplined anti-analysis architecture: two purpose-built domains deploying keyed URL access control, real-time browser fingerprinting via User-Agent Client Hints, per-victim randomized path generation, and a delivery-confirmation pixel beacon — four independent mechanisms operating in concert to profile victims, gate payload access, and frustrate automated detection, all before a single…
#APT29#CozyBear#spearphishing#browserfingerprinting#User-AgentClientHints#energysector#keyedURLaccesscontrol#campaigninfrastructureActorsAPT29 · MinidionisIOCf0 · i1 · d2 · u15MITRE4IndustriesEnergy
APTMembersJun 3, 2026, 04:08 (UTC+9)Complete Mimikatz Toolkit Deployed in Telecom Credential Campaign
A fully intact Mimikatz 2.2.0.0 distribution — kernel driver, main executable, credential-interception DLL, PrintNightmare exploit module, and distribution archive, all ten components present across both x64 and x86 architectures — has been deployed alongside Impacket ntlmrelayx Python relay scripts and cross-platform Chisel tunnel binaries in a campaign targeting the telecommunications sector.
#Mimikatz#Impacketntlmrelayx#Chisel#PrintNightmare#NTLMrelay#credentialharvesting#telecommunications#ActiveDirectoryActorsSandworm · QuedaghIOCf22 · i0 · d0 · u0MITRE12IndustriesTelecommunications
APTMembersJun 2, 2026, 16:01 (UTC+9)Valid BitTorrent Certificate Smuggles Trojan Past Endpoint Defences
A trojanised uTorrent Web installer bearing a currently-valid BitTorrent Inc code-signing certificate — serial 07 57 ED 74 D0 2A B0 00 FE AB 74 59 A3 34 CB 63, issued by DigiCert and valid through 2026-12-16 — is circulating as a dropper for a multi-stage payload chain that combines living-off-trusted-infrastructure staging, a repurposed censorship-circumvention tool, and a scripted certificate-rotation playbook on adjacent Hurricane Electric addresses.
#code-signingabuse#UltraSurf#HurricaneElectric#NSISInetc#living-off-trusted-infrastructure#Tortunnelling#certificaterotation#trojandropperActorsMuddyWater · TEMP.ZagrosIOCf4 · i3 · d0 · u0MITRE15
APTMembersJun 2, 2026, 01:04 (UTC+9)Trojanized Antivirus Suite Hides C2 in Alibaba CDN for Three Years
Ten malicious Windows DLLs, all signed within a single four-minute window on the morning of 30 August 2023, are circulating as components of a trojanized Chinese-language antivirus suite — and the operators behind them have constructed a delivery chain so thoroughly wrapped in legitimate infrastructure that three of the most common first-line defences fail simultaneously. The certificate is real. The domain is six years old.
#code-signingabuse#CDNblending#adware#dropper#Chinese-languagesoftware#DigiCertcertificate#AlibabaKunlunCDN#anti-analysisevasionActorsAPT28 · StrontiumIOCf16 · i32 · d1 · u10MITRE12
APTMembersJun 1, 2026, 20:47 (UTC+9)Five-Year Cert Rotation Engine Keeps Chinese-Ecosystem Malware Signed
Nine Windows executables and DLLs masquerading as MultiWeChat, TabX Explorer, Ludashi system utilities, and WPS Office components have been circulating with valid DigiCert code-signing certificates — not because a single company's identity was stolen, but because whoever operates this campaign has maintained sustained access to DigiCert's G4 code-signing infrastructure through six distinct Chinese-registered legal entities across a span of nearly five years.
#APT28#certificaterotation#codesigningabuse#Ludashi#QJWMonkey#CDNfronting#Chinesesoftwareecosystem#DigiCertActorsAPT28 · StrontiumIOCf11 · i6 · d4 · u1MITRE10
APTMembersJun 1, 2026, 17:20 (UTC+9)Fifteen New Addresses Cluster Inside One China Mobile ASN
Seventeen IP indicators sit in this record, and fourteen of them are new to this pass. Almost all of them — fifteen of the seventeen — resolve inside a single autonomous system: AS9808, registered to China Mobile Communications Group Co., Ltd. That concentration is the most consequential fact in this update, eclipsing the signed-binary story that anchored earlier coverage of this cluster.
#SaltySpider#PubNubRAT#AS9808#ChinaMobilecarrierinfrastructure#wildcardTLScertificateabuse#signedadware#codesigningcertificate#CDNspoofingActorsSalty Spider · KuKuIOCf103 · i17 · d1 · u1MITRE17
APTMembersJun 1, 2026, 10:22 (UTC+9)Chengdu Operator Hides RAT Inside Adware Using Dual DigiCert Certs
Nineteen of twenty Windows executables and DLLs circulating under fake Chinese security-product brands — SafeSpace, ByteLocker, DataVault, LhpMaxProtect, LhpNetSentinel, and a half-dozen others — carry valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, a signed-binary abuse strategy [T1553.002] that drives detection ratios as low as 12 of 76 engines on the largest payloads.
#PubNubRAT#Ludashi#code-signingabuse#certificateevasion#telecommunicationssector#Chengdu#adware-as-cover#C2infrastructureActorsFIN6 · Skeleton SpiderIOCf54 · i11 · d10 · u14MITRE10IndustriesTelecommunications
APTMembersMay 31, 2026, 23:52 (UTC+9)Void Arachne Splits DigiCert Abuse Across Three Firms to Outrun Revocation
Eight PE32 executables dressed as consumer disk cleaners and Android emulator components are circulating with valid DigiCert G4 code-signing certificates obtained under three distinct Chinese legal entities — a deliberate identity-fragmentation strategy that keeps each certificate clean while a shared packing toolchain quietly links the clusters behind the scenes.
#VoidArachne#SilverFox#DigiCertcode-signingabuse#PubNubRAT#certificatefragmentation#ChinaMobileinfrastructure#trojanisedutilitysoftware#C2camouflageActorsVoid Arachne · Silver FoxIOCf11 · i2 · d5 · u4MITRE4
APTMembersMay 31, 2026, 19:32 (UTC+9)Valid DigiCert Cert Turns 2345 SafeCenter Update Channel Into Malware Pipeline
Seventeen Windows PE files masquerading as components of the 2345 SafeCenter security suite and HaoZip archiver are circulating with a currently-valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd. — a credential that suppresses Windows SmartScreen warnings and causes automated sandbox platforms to return clean verdicts on samples that 25 to 38 static antivirus engines simultaneously flag as adware.
#SaltySpider#ad2345#Chinad#code-signingabuse#SQLServerauthenticationbypass#CDN-hostedpayloaddelivery#sandboxevasion#ChinaActorsAPT28 · StrontiumIOCf17 · i41 · d1 · u2MITRE8
APTMembersMay 31, 2026, 17:42 (UTC+9)TA505 ServHelper C2 Expands: Three DGA Domains, One Operator Fingerprint
Four new command-and-control domains and eight associated URLs have surfaced in the ongoing ServHelper campaign tracked by CTX Team, extending a C2 infrastructure cluster whose internal consistency is striking in its operational discipline. The new additions — three algorithmically generated .xyz domains and a structurally isolated .cn outlier — carry fingerprints that converge on a single provisioning workflow: identical obfuscated WHOIS registrant tokens, uniform nameserver delegation through…
#TA505#ServHelper#C2infrastructure#DGAdomains#RDPWrap#Let'sEncryptabuse#certificatetransparency#WHOISobfuscationActorsTA505 · Hive0065IOCf16 · i1 · d4 · u8MITRE43
APTMembersMay 31, 2026, 17:24 (UTC+9)Salty Spider Hides Espionage Tool in Decade-Old Adware Bundle
A 2.3-megabyte Windows executable bearing "iMesh Inc" copyright metadata is circulating as what appears to be a routine peer-to-peer client installer — but the binary, tracked by CTX Team as iMeshV22.exe, bundles the Cydoor and SaveNow adware families inside a delivery chain that combines PEiD and Armadillo packing, active debugger detection, and a version-check beacon that registers each new victim with encoded telemetry.
#SaltySpider#Cydoor#SaveNow#adware#sandboxevasion#educationsector#France#trojanisedinstallerActorsSalty Spider · KuKuIOCf18 · i0 · d4 · u2MITRE43RegionsFR · GB · NCIndustriesEducation & Research
APTPublicMay 31, 2026, 08:29 (UTC+9)Single DigiCert Certificate Ties 11 Trojanized Files Across Two 2345 Product Lines
Eleven Windows executables and DLLs, all bearing a currently valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd., have been confirmed as part of an expanding trojanized software campaign that now spans two distinct 2345 product lines — the SafeCenter security suite and the HaoZip archiving utility — across two coordinated build events separated by twenty days.
#Shanghai2345MobileTechnology#code-signingabuse#DigiCertcertificate#SafeCenter#HaoZip#sandboxevasion#AlibabaCDN#Skip-2.0ActorsAPT28 · StrontiumIOCf17 · i43 · d1 · u2MITRE8
APTMembersMay 31, 2026, 04:42 (UTC+9)One DigiCert Certificate, 14 Malicious Binaries, 18 Months Unrevoked
A single unrevoked DigiCert code-signing certificate — issued to the Chinese entity 成都奇鲁科技有限公司 and carrying serial number 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid from May 21, 2024 through May 20, 2027 — has been used to sign 14 distinct malicious Windows binaries deployed across at least six consumer-facing product brands over an 18-month window.
#Ludashi#code-signingabuse#PUAadware#CDNfronting#TencentAPIGateway#telecommunications#China#SuperAppActorsFIN6 · Skeleton SpiderIOCf26 · i1 · d7 · u12MITRE10IndustriesTelecommunications
APTMembersMay 30, 2026, 20:24 (UTC+9)Sims 4 Crack Lure Delivers CyberGate RAT Across Nine Countries
Three Windows executables dressed as Sims 4 crack installers and updaters are circulating across nine countries, carrying a CyberGate/Rebhip remote access trojan beneath a multi-layer evasion stack that combines NSIS dropper wrapping, active sandbox product-ID detection, and XOR-obfuscated PE stubs — a tradecraft combination deliberately engineered to defeat automated analysis pipelines before a human analyst ever sees the payload.
#Snowglobe#CyberGate#Rebhip#NSISdropper#sandboxevasion#educationsector#telecommunications#DDNSinfrastructureActorsSnowglobe · Animal FarmIOCf10 · i0 · d1 · u1MITRE41RegionsBE · LT · PL · RSIndustriesEducation & Research · Telecommunications
APTMembersMay 30, 2026, 10:44 (UTC+9)Chrome-Impersonating Mach-O Binaries Hit Government Macs With 0/76 AV Detections
Two universal Mach-O binaries impersonating Google Chrome — signed with a valid Apple Developer-issued certificate bearing the Google LLC identity, yet carrying a MissingPlist code-signing verdict that defeats Gatekeeper's full bundle validation — are circulating against government-sector macOS targets with zero detections across 76 antivirus engines.
#Cactus#MissingPlist#macOS#governmentsector#signedbinaryabuse#DNS-over-HTTPS#Chromeimpersonation#Mach-OActorsCactus · Cactus Ransomware GroupIOCf2 · i2 · d4 · u4MITRE5IndustriesGovernment
APTMembersMay 30, 2026, 06:22 (UTC+9)One Code-Signing Cert, 15 Malware Families, Valid Until 2027
A single DigiCert code-signing certificate issued to a Chinese commercial entity has been used to sign 15 distinct malicious PE32 executables spanning six threat families over a twelve-month window — and it remains valid through May 2027. The certificate, issued to 成都奇鲁科技有限公司 (serial 0D078E70EAEE48FFEB9576BDD400BE98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0), has functioned as a persistent OS-level trust bypass [T1553.002] across the entire payload portfolio, enabling malicious…
#SaltySpider#Ludashi#Chinad#Doina#code-signingabuse#ChinesePUAecosystem#signedbinaryproxyexecution#certificaterevocationgapActorsGroup123 · Venus 121IOCf23 · i5 · d2 · u0MITRE16
APTMembersMay 30, 2026, 00:33 (UTC+9)SmokeLoader Campaign Adds Trojanized Card-Checker Lure, Third C2 Node
Since CTX Team's earlier coverage of this SmokeLoader-driven infostealer operation, seven new file indicators have surfaced alongside a full refresh of the campaign's three command-and-control IPs — and the most significant development is not the infrastructure update but what it reveals about how the operator is now getting onto victim machines.
#SmokeLoader#trojan.marsilia#APT39#infostealer#bulletproofhosting#Spain#cryptocurrencytheft#logmarketplaceActorsAPT39 · ChaferIOCf35 · i3 · d0 · u5MITRE48RegionsES
APTMembersMay 29, 2026, 19:27 (UTC+9)Two Shell Companies, Two DigiCert Certs, One Ludashi Campaign
Twenty Windows executables and DLLs carrying currently-valid DigiCert code-signing certificates are circulating across telecom-sector endpoints, each one disguised as a routine Windows system utility — a PC cleaner, a BSOD repair tool, a browser protection suite — and each one backed by a C2 cluster that routes through China Unicom's backbone while presenting financial-services TLS cover.
#FIN6#TA428#lockergoga#ncctrojan#lummastealer#TelecommunicationsActorsFIN6 · Skeleton SpiderIOCf29 · i2 · d4 · u4MITRE6IndustriesTelecommunications
APTMembersMay 29, 2026, 18:20 (UTC+9)Revoked Certum Cert Evades 75 of 76 Engines in Ludashi Adware Pivot
Two freshly minted Windows executables, both signed by a previously unseen Chinese entity called 深圳市禹仁科技有限公司 and both carrying a Certum code-signing certificate that had already been revoked at the time of deployment, surfaced on VirusTotal on 23 May 2026 — just six days before CTX Team's analysis. One of the two files, a 346-kilobyte PE32 executable installed under C:\Program Files (x86)\ProZip\Bin\nhlj32.exe, was flagged by exactly one of 76 scanning engines.
#FIN6#SaltySpider#lockergoga#lummastealer#salityActorsFIN6 · Skeleton SpiderIOCf26 · i11 · d10 · u8MITRE16
APTMembersMay 29, 2026, 17:53 (UTC+9)Four Shell Companies, One CA: How Ludashi Buries Payloads in Trusted Certs
Seventeen Windows executables and DLLs. Four distinct Chinese corporate identities. A single DigiCert intermediate certificate authority threading through all of them. That is the structural core of a Ludashi adware and trojan campaign that CTX Team has been tracking across a ten-month payload timeline stretching from July 2025 through late May 2026 — a campaign that uses rotating shell-company code-signing certificates, deliberate PE header corruption, and a pre-staged CDN infrastructure built…
#PatchworkActorsPatchwork · ChinastratsIOCf20 · i8 · d10 · u52MITRE18
APTMembersMay 29, 2026, 10:16 (UTC+9)Ludashi Campaign Expands C2 Layer With Cloud Proxy Evasion
Since CTX Team's earlier coverage of this campaign, the observable payload set has contracted while the network infrastructure has expanded dramatically — 21 new IP addresses, six new C2 domains, and seven new URLs have entered the picture, with zero new file payloads added. The delta is entirely in the network layer, and what it reveals is a meaningful escalation in how the operators route and obscure their command-and-control traffic.
#TA551#icedidActorsTA551 · ShathakIOCf19 · i21 · d6 · u7MITRE12
APTMembersMay 29, 2026, 10:04 (UTC+9)Emotet Revives 18-Year-Old Domains in Coordinated Chile Campaign
Three .com domains registered between November 2007 and January 2008 — old enough to predate the iPhone's first software update cycle — have been quietly reactivated as payload-staging and command-and-control nodes for an Emotet-linked campaign targeting Chile. The reactivation was not gradual. Between 17 April and 4 May 2026, all three domains received fresh 89-day Let's Encrypt certificates within a compressed 17-day window, a coordinated provisioning pass that CTX Team's analysis identifies…
#EmotetGroup#emotetActorsEmotet Group · TA542IOCf3 · i2 · d3 · u6RegionsCL
APTMembersMay 29, 2026, 09:53 (UTC+9)Trojanised Dr.Fone Installer Delivers VjW0rm via Three-Continent CDN-Masquerade C2
Nine new file indicators and one additional command-and-control IP have been added to the TA2541-linked VjW0rm cluster since earlier coverage, expanding a campaign whose most operationally distinctive feature was never the payload itself but the infrastructure architecture surrounding it: three geographically dispersed servers, each presenting a wildcard-SAN TLS certificate impersonating a different major CDN brand, observed within a 48-hour window and spread across three separate autonomous…
#TA2541#VjW0rm#CDNimpersonation#NSISdropper#JavaScriptworm#C2infrastructure#EgyptFranceRomaniaUnitedStates#OperationLayoverActorsTA2541 · Operation LayoverIOCf17 · i3 · d1 · u2RegionsEG · FR · RO · US
APTMembersMay 29, 2026, 05:53 (UTC+9)One Unrevoked Certificate, 18 Builds: Inside a 14-Month Adware Campaign
A DigiCert code-signing certificate issued to a Chengdu technology company has been used continuously for more than 14 months to sign trojanized Windows executables masquerading as components of LuDaShi (鲁大师), one of China's most widely installed PC-optimization suites — and that certificate remains unrevoked today. CTX Team's latest sweep of the campaign has surfaced 41 new file indicators alongside a purpose-built command-and-control domain pair registered in December 2025 that carries a 0/91…
#FIN6#TA428#Group123#lockergoga#ncctrojan#lummastealerActorsFIN6 · Skeleton SpiderIOCf60 · i27 · d4 · u1MITRE13
APTMembersMay 29, 2026, 01:53 (UTC+9)Three DigiCert Certs, One Builder: Inside a Chinese Adware Signing Pipeline
Somewhere between a disk-cleaner utility and a remote-access implant, a modular Windows toolkit has been quietly circulating across Chinese software distribution channels, its every component bearing a valid DigiCert code-signing certificate issued to a registered Chinese legal entity. The campaign — tracked by CTX Team across at least 41 PE32 files and 20 confirmed network endpoints — deploys under four consumer-software personas (DupsClean, LargeFileClean, BirdWallpaper, and BlueDoveUnist)…
#APT33#shapeshift#icedidActorsAPT33 · MagnalliumIOCf41 · i77 · d3 · u2MITRE15
APTMembersMay 28, 2026, 21:56 (UTC+9)Dual DigiCert Certs Cloak Adware-to-RAT Campaign Across 19 Payloads
##A Single Certificate, Nineteen Signed Payloads, and a RAT Hidden Inside an Adware Framework Nineteen Windows binaries carrying valid DigiCert code-signing certificates — issued to two distinct Chinese-registered entities — have been circulating across Mandarin-language software distribution channels for at least eight months, wrapping a Ludashi/PolarWind adware framework around a RAT-capable core that most endpoint products still cannot see clearly.
#FIN6#TA428#APT23#lockergoga#ncctrojan#lummastealerActorsFIN6 · Skeleton SpiderIOCf61 · i5 · d3 · u3MITRE20
APTMembersMay 28, 2026, 05:53 (UTC+9)Signed DLL in Adware Chain Confirmed as PubNubRAT
For eighteen months, a campaign built around two DigiCert code-signing certificates issued to Chengdu-registered entities moved through Chinese-language Windows environments largely beneath the noise floor — its payloads labelled adware, its delivery mechanism a well-known PC-utility ecosystem, its detection rates low enough that signed binaries slipped past Windows SmartScreen with detection ratios as low as 10 of 77 engines. That picture changed with the appearance of a single DLL.
#APT23#lummastealerActorsAPT23 · KeyBoyIOCf28 · i26 · d2 · u3MITRE13
APTMembersMay 28, 2026, 01:59 (UTC+9)Ludashi Campaign Adds 13 Payloads, Tencent CDN Relay to Evasion Stack
Thirteen new Windows PE32 binaries signed under a single DigiCert code-signing certificate have entered the Ludashi-ecosystem campaign since CTX Team's prior coverage, while a freshly provisioned four-subdomain C2 cluster under tjbxldkj.cn and a Tencent Cloud API Gateway domain-fronting relay on ss.dllfix.cn represent infrastructure capabilities that were absent from the earlier operation.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf32 · i23 · d6 · u8MITRE12
APTMembersMay 27, 2026, 06:02 (UTC+9)Trojanised Office Tool Hides Multi-Stage Intrusion Behind Streaming C2
A trojanised version of OfficeRTool — a popular Microsoft Office removal and activation utility distributed through piracy channels — is serving as the entry point for a disciplined, multi-phase intrusion operation that layers sandbox-evading VBScript components, a vhash-identical PowerShell downloader maintained across at least six major tool versions, expired-certificate network reconnaissance, and a command-and-control channel engineered to look indistinguishable from HLS media streaming…
#LockbitGang#expiro#GovernmentActorsLockbit GangIOCf7 · i3 · d2 · u8MITRE11IndustriesGovernment
APTMembersMay 27, 2026, 05:51 (UTC+9)Expired-Cert Installer Evades Sandboxes, Feeds 15-Domain Crypto Fraud Net
A 4.3-megabyte Windows installer, dressed in the branding of legitimate freeware and carrying a Sectigo-issued code-signing certificate that had already expired, is the entry point for a financially motivated campaign that routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains.
#APT28#APT15#bumblebee#EnergyActorsAPT28 · StrontiumIOCf62 · i6 · d15 · u11MITRE12IndustriesEnergy
APTMembersMay 27, 2026, 00:03 (UTC+9)APT28 Splits EV Certificate and LummaC2 Stealer Across Two-Tier Chain
Four Windows executables carrying a valid Extended Validation code-signing certificate issued to an entity called ORYON TECH LIMITED are circulating as a disguised system-utility package — while a pair of freshly compiled LummaC2 stealers, deliberately stripped of any trusted certificate chain, rides the same delivery infrastructure toward the same targets. The deliberate split is not an oversight.
#APT28#gcleaner#TechnologyActorsAPT28 · StrontiumIOCf21 · i2 · d5 · u8RegionsUSIndustriesTechnology
APTMembersMay 26, 2026, 23:45 (UTC+9)Signed, Sealed, Trojanized: Dual Chengdu Certs Power RAT Campaign
Eighteen Windows PE32 files — executables and DLLs impersonating Ludashi SuperApp system utilities — are circulating with currently-valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, producing uniformly clean sandbox verdicts despite industry detection ratios that reach as high as 34 of 76 engines.
#Turla#FIN6#Group123#lockergoga#ncctrojan#xtreme_ratActorsTurla · Iron HunterIOCf57 · i27 · d7 · u1MITRE16IndustriesTelecommunications
APTMembersMay 26, 2026, 22:24 (UTC+9)FunkSec macOS Implant Evades 76 AV Engines via Fake Chrome Signing
Two Mach-O universal binaries named com.google.Chrome.helper — each 166 kilobytes, each signed with a structurally present but functionally invalid Google LLC code-signing certificate, each returning zero detections across all 76 antivirus engines on VirusTotal — are circulating as part of a campaign CTX Team has attributed to FunkSec, targeting engineering and government sector organisations operating macOS endpoints.
#FunkSec#Engineering#GovernmentActorsFunkSecIOCf2 · i12 · d47 · u31MITRE8IndustriesEngineering · Government
APTMembersMay 26, 2026, 22:03 (UTC+9)Salty Spider Turns Revoked Certificates Into a 71/76 Evasion Tool
Two Windows executables submitted to public malware repositories on 23 May 2026 — both signed with a code-signing certificate that had already been revoked by its issuing CA — cleared 71 of 76 scanning engines without triggering a single alert. The files, bearing the product description "Pro解压缩" (Pro Decompression) and the internal name uninst.exe, were the freshest output of a campaign that CTX Team has been tracking across a ten-month arc stretching from July 2025 to the present.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf15 · i1 · d8 · u3MITRE42
APTMembersMay 26, 2026, 16:35 (UTC+9)Two DigiCert Certs, 18 Signed Payloads, 14 Months Unrevoked
Eighteen Windows executables and DLLs have been circulating under the cover of two valid DigiCert Trusted G4 code-signing certificates, each issued to a distinct Chinese legal entity, across a campaign that CTX Team has tracked from November 2024 through at least January 2026. Both certificates remain unrevoked. Every file in the cohort passes Windows Authenticode validation without a SmartScreen warning.
#FIN6#SaltySpider#lockergoga#lummastealer#salityActorsFIN6 · Skeleton SpiderIOCf32 · i8 · d10 · u12MITRE19
APTMembersMay 26, 2026, 10:12 (UTC+9)Trojanized Adware Chain Hides Behind Bank's TLS Identity for 12 Months
Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 have been circulating as trojanized PC-utility components since at least May 2025 — all signed under a single certificate serial (0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0) that remains unrevoked and valid through May 2027.
#FIN6#lockergoga#lummastealer#expiro#TelecommunicationsActorsFIN6 · Skeleton SpiderIOCf20 · i18 · d0 · u1MITRE8IndustriesTelecommunications
APTMembersMay 26, 2026, 09:59 (UTC+9)Single EV Certificate Signed Trojan.Jumper Trio Across Nine Sectors
A trojanised VPN installer toolchain — three PE32 binaries all bearing a single GlobalSign Extended Validation certificate issued to "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — has been circulating across nine industry verticals since at least September 2025, using a curated software-recommendation channel as its entry point and a three-tier command-and-control architecture to evade both sandbox analysis and network-level detection.
#TA551#EducationResearch#Engineering#Financial#FoodBeverages#GovernmentActorsTA551 · ShathakIOCf3 · i4 · d2 · u1MITRE29IndustriesEducation & Research · Engineering · Financial Services
APTMembersMay 26, 2026, 09:41 (UTC+9)APT23 Runs 18-Month Signed-Binary Campaign Behind Chinese Corporate Certs
Eight Windows executables have been circulating across Chinese-language computing environments since at least November 2024, each carrying a valid, unexpired DigiCert G4 code-signing certificate issued to one of three distinct Chinese corporate entities — and each producing uniformly clean verdicts in automated sandbox environments despite antivirus detection ratios that range as high as 34 out of 76 engines.
#APT23#lummastealer#icedid#neshtaActorsAPT23 · KeyBoyIOCf12 · i2 · d9 · u11MITRE13
APTMembersMay 24, 2026, 17:57 (UTC+9)One Unrevoked Certificate, 17 Payloads, Eleven Months of Signed Adware
Seventeen distinct Windows executables. Six product identities. Eleven months of continuous distribution. All of it bound together by a single DigiCert G4 code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co., Ltd.) — a certificate that, as of this writing, remains valid, unrevoked, and good until May 2027.
#FIN6#Group123#SaltySpider#lockergoga#lummastealer#salityActorsFIN6 · Skeleton SpiderIOCf34 · i3 · d6 · u6MITRE11