APTMembersMay 24, 2026, 13:30 (UTC+9) Cactus Group Abuses Three Signing Identities to Hide PBot Stealer in VPN Lures
Nine Windows executables circulating across software-distribution channels share a single operational logic: every one of them carries a legitimate code-signing certificate — or a certificate that was legitimate until recently — and every one of them is doing something the signer never intended. Six files exploit expired-but-chain-valid EV and OV certificates from two distinct corporate identities to suppress antivirus detection on trojanized VPN installers.
#Cactus#ramnit
ActorsCactus · Cactus Ransomware GroupIOCf16 · i46 · d118 · u16MITRE16