APTMembersMay 24, 2026, 14:01 (UTC+9)Salty Spider Hides RAT in Signed Bundles via Two DigiCert Certs
Twenty malicious Windows executables and DLLs have been circulating under valid DigiCert G4 code-signing certificates issued to two Chinese-registered front entities — a dual-certificate architecture that has remained unrotated across a fifteen-month active build window while the operator quietly embedded a PubNubRAT remote-access capability inside what presents to users as a routine system-utility bundle.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf33 · i7 · d6 · u5MITRE14
APTMembersMay 24, 2026, 13:30 (UTC+9)Cactus Group Abuses Three Signing Identities to Hide PBot Stealer in VPN Lures
Nine Windows executables circulating across software-distribution channels share a single operational logic: every one of them carries a legitimate code-signing certificate — or a certificate that was legitimate until recently — and every one of them is doing something the signer never intended. Six files exploit expired-but-chain-valid EV and OV certificates from two distinct corporate identities to suppress antivirus detection on trojanized VPN installers.
#Cactus#ramnitActorsCactus · Cactus Ransomware GroupIOCf16 · i46 · d118 · u16MITRE16