CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • APTMembersMay 24, 2026, 14:01 (UTC+9)

    Salty Spider Hides RAT in Signed Bundles via Two DigiCert Certs

    Twenty malicious Windows executables and DLLs have been circulating under valid DigiCert G4 code-signing certificates issued to two Chinese-registered front entities — a dual-certificate architecture that has remained unrotated across a fifteen-month active build window while the operator quietly embedded a PubNubRAT remote-access capability inside what presents to users as a routine system-utility bundle.

    #SaltySpider#sality
    ActorsSalty Spider · KuKuIOCf33 · i7 · d6 · u5MITRE14
  • APTMembersMay 24, 2026, 13:30 (UTC+9)

    Cactus Group Abuses Three Signing Identities to Hide PBot Stealer in VPN Lures

    Nine Windows executables circulating across software-distribution channels share a single operational logic: every one of them carries a legitimate code-signing certificate — or a certificate that was legitimate until recently — and every one of them is doing something the signer never intended. Six files exploit expired-but-chain-valid EV and OV certificates from two distinct corporate identities to suppress antivirus detection on trojanized VPN installers.

    #Cactus#ramnit
    ActorsCactus · Cactus Ransomware GroupIOCf16 · i46 · d118 · u16MITRE16
1Of
4
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.