C&CMembersAug 13, 2026, 06:28 (UTC+9)Seven Malware Family Labels Turn Out to Be One StealC Codebase
Eleven files sitting behind a single command-and-control cluster were flagged by vendor engines as seven different malware families — StealC v2, TinyNuke, PowerLoader, Carberp, Vidar, RedLine and a Telegram-adjacent stealer tracked as MaskGramStealer. Six independent YARA rulesets and a run of IDS signatures tell a different story: several of these "families" are the same codebase and the same command-and-control protocol, wrapped in different crypto-themed lure names and shipped through…
#StealC#TinyNuke#RedLine#Vidar#MaskGramStealer#command-and-controlinfrastructure#cryptoluremalware#AS214351IOCf11 · i4 · d1 · u11MITRE45RegionsPK · USIndustriesTechnology · Telecommunications
C&CMembersAug 11, 2026, 14:48 (UTC+9)Bright Data-Signed EarnApp Loader Unchanged as 66 New Domains Surround It
The malicious file cluster that CTX Team first catalogued around a Bright Data Ltd-signed EarnApp installer has not moved: the same four binaries, the same DigiCert Trusted G4 Code Signing chain, the same detection spread running from 9 of 75 engines to 24 of 76. What has moved, sharply, is everything sitting around it. This snapshot adds 66 new domains and 19 new IPs against just 9 new file hashes — an order of magnitude more growth in registration and certificate infrastructure than in…
#EarnApp#BrightData#PBotstealer#codesigningabuse#domainregistrationfraud#Let'sEncryptcertificates#residentialproxymalware#APT28attributionActorsAPT28 · StrontiumIOCf78 · i24 · d91 · u11MITRE2IndustriesCommercial Services
C&CMembersAug 11, 2026, 06:38 (UTC+9)One DigiCert Chain, Three Chengdu Shells, 12 Signed Adware Installers
A rotating cast of Chengdu-registered shell companies has spent the past eighteen months feeding disposable code-signing identities into a single DigiCert trust chain, and the resulting installers are still walking past static AV and sandbox alike. Twelve Windows binaries examined here — installer stubs for C-drive cleaners, ad blockers, and "system optimizer" tools bundled under LuDaShi/SuperApp-style directory trees — all chain up through the same DigiCert Trusted G4 Code Signing RSA4096…
#code-signingabuse#DigiCertcertificate#Chineseadware#LudashiPUA#shellcompanysigners#sandboxevasion#APT29misattribution#ChinaTelecomJiangsuinfrastructureActorsAPT29 · MinidionisIOCf23 · i2 · d0 · u0MITRE26IndustriesWholesale
C&CMembersAug 10, 2026, 22:37 (UTC+9)Lazarus Label Rides on Thin Evidence: Old Domains, Shared Certs
A cluster of internet infrastructure carrying a Lazarus Group label arrived this month with almost nothing behind it: 29 file hashes with no signer, no size, no threat classification attached to any of them, and fifteen network indicators that sit at 0 or 1 detection out of 91 security engines, with zero community votes either way.
#LazarusGroup#mimail#certificatereissuance#CDNfronting#Incapsula#Namecheapdomains#threatattribution#commandandcontrolinfrastructureActorsLazarus Group · Hastati GroupIOCf29 · i7 · d8 · u0RegionsDE
C&CMembersAug 9, 2026, 10:54 (UTC+9)Chinese Adware Ring Reuses Certs to Spoof UnionPay and Huawei
Every piece of command infrastructure in this record — all seven IP addresses tied to the cluster — sits on a single Chinese carrier backbone, AS4837, CHINA UNICOM China169 Backbone. That alone would be a footnote for China-facing infrastructure. What makes it a story is what those IPs present to anyone who connects to them: two separate, duplicated TLS certificates, each spoofing a different trusted brand.
#code-signingabuse#TLScertificatespoofing#UnionPayimpersonation#HuaweiAppGalleryspoofing#ChinaUnicomAS4837#ludashiadware#anti-analysistechniques#PUAdistributionIOCf28 · i7 · d0 · u0MITRE14
C&CMembersAug 8, 2026, 20:44 (UTC+9)Valid Bright Data Signature Found on EarnApp Installers Flagged as PBot Stealer
Four Windows installers branded as EarnApp — the passive-income tool that pays users to resell idle bandwidth through Bright Data's proxy network — carry a fully valid Bright Data Ltd code-signing chain from DigiCert, and two of them are independently flagged by a sandbox as the "PBot" stealer family. That combination is the story here, not because a certificate was forged or revoked, but because it wasn't.
#EarnApp#BrightData#PBotstealer#code-signingabuse#DigiCert#supply-chaintrustabuse#proxyware#bandwidth-sharingmalwareIOCf69 · i22 · d98 · u9MITRE4IndustriesCommercial Services
C&CMembersAug 8, 2026, 19:39 (UTC+9)Fake UnionPay TLS Certificate Ties Together 19 Chinese Adware Hosts
Nineteen IP addresses scattered across five or more distinct Chinese ISPs — China Unicom's China169 backbone, three separate China Mobile autonomous systems, and a scatter of regional China Telecom blocks — all present the identical TLS certificate when a browser connects to them. The subject line reads *.unionpayintl.com, organisation "UnionPay International Co., Ltd.," issued by DigiCert's Basic OV G2 TLS CA.
#UnionPayimpersonation#wildcardTLScertificate#Ludashi#Chinad#PolarWind#codesigningabuse#APT23#adwaredistributioninfrastructureActorsAPT23 · KeyBoyIOCf17 · i23 · d2 · u0MITRE7
C&CMembersAug 8, 2026, 14:23 (UTC+9)One Chinese Certificate Signed Nine Months of Ludashi Adware Builds
The most durable piece of infrastructure behind a sprawling family of Chinese system-utility adware is not a server or a domain — it is a single code-signing certificate. Eight of nine binaries examined in this cluster carry an identical signer chain: 成都奇鲁科技有限公司, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert's root, with certificate serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98.
#Ludashiadware#code-signingcertificateabuse#ChinaD#UnwantedX#wildcardTLScertificate#China-basedinfrastructure#adwareC2#PUAdistributionActorsFIN6 · Skeleton SpiderIOCf9 · i2 · d4 · u3MITRE11
C&CMembersAug 6, 2026, 22:12 (UTC+9)C2 Cluster Adds 9 IPs, 20 Domains — Just 5 New Files
Nine new IP addresses and twenty new domains have surfaced around a C2-server cluster CTX Team has been tracking since earlier coverage of a campaign built on trojanized VPN and proxy installers ("Two Vendor Signatures, One Stealer"). Only five new files joined the set in the same window. That lopsided ratio is itself the story: the operators are not retooling their malware, they are aggressively provisioning and rotating the network fabric that fronts it.
#C2infrastructure#trojanizedinstallers#WireVPN#BrightDataimpersonation#certificatereuse#SpacePirates#Cactus#disposableinfrastructureActorsSpace Pirates · WebwormIOCf14 · i21 · d47 · u6MITRE16
C&CMembersAug 5, 2026, 22:13 (UTC+9)Batch-Signed Adware Beats AV Detection, Fools Every Sandbox
A code-signing certificate issued to a company called Shenzhen Kaixin Kangaroo Technology Co., Ltd. was used to sign eight different executables and DLLs — all in the same eight-minute window on March 20, 2024. A separate certificate, issued this time to Shanghai Oriental Webcasting Co. Ltd., produced the same pattern two months later: seven of eight files signed within a single minute on May 29, 2024.
#code-signingcertificateabuse#adware#PUA#GoodZip#WanNengWBInput#APT27#SaltySpider#ChinaCDNinfrastructureActorsAPT27 · TEMP.HippoIOCf30 · i14 · d1 · u1MITRE24
C&CMembersAug 5, 2026, 11:41 (UTC+9)Two Vendor Signatures, One Stealer: VPN Installers Abuse Trust Chains
Three files circulating under VPN branding this year carry a code-signing chain that VirusTotal's own signer inspection flags as broken. The signer field reads "WEILAI NETWORK TECHNOLOGY CO., LIMITED," countersigned through GlobalSign GCC R45 EV CodeSigning CA 2020, and every one of the three samples' signer-details blocks returns the same line: "This certificate or one of the certificates in the certificate chain is not time valid." That should be a hard stop for any endpoint relying on…
#code-signingabuse#PBotstealer#BrightData#WEILAINETWORKTECHNOLOGY#VPNinstallertrojan#fast-fluxhosting#Let'sEncryptabuse#SpacePiratesActorsSpace Pirates · WebwormIOCf9 · i15 · d27 · u3MITRE17
C&CMembersAug 3, 2026, 05:32 (UTC+9)APT28-Tagged Cluster Shows 89-Day Cert Pattern, No Malware
Three domains with nothing else in common — different registrars, different creation dates, different Let's Encrypt intermediates — share one oddly precise trait: certificates valid for exactly 89 days. ccu.to, swisscutterastronaut.com, and each-task.com were issued certificates by three separate Let's Encrypt intermediates (R13, YR2, and YE1, respectively), yet all three validity windows run to the same 89-day span.
#APT28#FancyBear#Let'sEncryptcertificates#certificatecloning#C2infrastructure#domainregistrationfraud#espionage#TencentCDNActorsAPT28 · StrontiumIOCf0 · i5 · d7 · u0MITRE4IndustriesContainers & Packaging
C&CMembersAug 2, 2026, 05:41 (UTC+9)Fake Baidu, Alibaba TLS Certs Mask Five-Year RAT Campaign
Ten IP addresses tied to a single threat-intelligence record show almost no malicious signal on their own — nine come back 0/91 on antivirus scanning, one scrapes a single flag at 1/91. Yet three of those IPs pair up with a twin elsewhere on the internet through an identical TLS certificate, and each pairing wildcards a domain the certificate's real owner has nothing to do with. Two Alibaba Cloud-registered addresses share one GlobalSign-issued certificate for .certfallback.com.
#XRedRAT#certificatereuse#TLSimpersonation#Baiduspoofing#AlibabaCloud#ChinaUnicom#APT28attribution#dynamicDNSC2ActorsAPT28 · StrontiumIOCf13 · i10 · d0 · u0MITRE40RegionsTW
C&CMembersAug 1, 2026, 05:38 (UTC+9)EV Certificate Lets ORYON Adware Suite Slip Past Sandbox Scans
Four differently named Windows installers — AdvancedWindowsManager.exe, Windows Updater.exe, Installer_1.0.0.exe and an MSI package called e78a2.msi — carry the exact same code-signing chain: ORYON TECH LIMITED, chaining through Sectigo Public Code Signing CA EV R36 and Sectigo Public Code Signing Root R46, all signed at the identical timestamp of 08:36 AM on 04/23/2026. That precision is the story.
#ORYONTECHLIMITED#EVcodesigningabuse#microleavesadware#sandboxevasion#pay-per-install#Cloudflareredirectordomains#QuickFetchloader#PUPdistributionIOCf20 · i1 · d5 · u15MITRE22RegionsBE · CA · DZ · GBIndustriesRetail · Technology
C&CMembersJul 31, 2026, 13:43 (UTC+9)Two 'Rival' Chinese Software Brands Share One Signing Chain
Fourteen signed Win32 binaries surfaced carrying the trusted names of two separate Chinese software vendors — a "万能五笔输入法" input-method utility from Shanghai Oriental Webcasting Co. Ltd. and a "2345看图王" photo-viewer suite from Shanghai 2345 Mobile Technology Co., Ltd. — yet both cohorts chain to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root, and a single YARA rule fires across samples signed by each.
#adware#codesigningabuse#DigiCert#China#CDNinfrastructure#YARAfingerprint#Group123/APT37misattribution#SalitymisattributionActorsGroup123 · Venus 121IOCf14 · i6 · d0 · u0MITRE28
C&CMembersJul 31, 2026, 05:44 (UTC+9)Shared Certificates, Not Payloads, Tie Five Emotet-Linked Domains
Five domains and a single Hostinger-hosted IP address form a hosting cluster that looks less like purpose-built command infrastructure and more like a disposable inventory kept in circulation for years. Across the set, two distinct certificate-issuer cohorts and a shared nameserver pairing tie the nodes together with far more precision than anything the lone piece of file telemetry in this record can offer. The strongest signal here isn't a payload — it's the paperwork.
#Emotet#TA542#C2infrastructure#Let'sEncryptcertificates#domainreuse#Hostinger#educationsector#macrodownloaderActorsEmotet Group · TA542IOCf3 · i1 · d5 · u2RegionsUSIndustriesEducation & Research
C&CMembersJul 30, 2026, 05:42 (UTC+9)One Reused Certificate Signs 20 Files in Wubi Input Adware Suite
Twenty separate executables and DLLs packaged as components of "万能五笔输入法" — the Universal Wubi Input Method, a Chinese-language input tool — all carry the identical Authenticode signature from "Shanghai Oriental Webcasting Co. Ltd.," chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, with the exact same certificate serial number (0B 03 D3 41 0E 57 67 8D F3 FC A1 3A 38 44 3E 84) stamped across every file.
#adware.softcnapp#code-signingabuse#Wubiinputmethod#DigiCertcertificatereuse#ChinanetCDNinfrastructure#PUAbundler#sandboxevasion#misattributedmalwarefamilyIOCf39 · i9 · d0 · u0MITRE10
C&CMembersJul 29, 2026, 13:43 (UTC+9)Fake Bright Data Signature Cloaks PBot Stealer in Update Lure
A Bright Data Ltd code-signing certificate — issued through DigiCert's Trusted G4 chain and still inside its 2025~2027 validity window — is authenticating a binary that a sandbox flags outright as the PBot stealer. The file, shipped internally as net_updater.exe, drops into install paths named "DriverHub" and "Bright VPN" [T1036.005], borrowing the visual language of a legitimate residential-proxy SDK to get past the trust checks that a valid signature is supposed to guarantee [T1553.002].
#PBotstealer#code-signingabuse#BrightData#transportationsector#C2infrastructure#PUAmasquerade#.NETpacker#DigiCertcertificateIOCf49 · i4 · d10 · u0MITRE6IndustriesTransportation
C&CMembersJul 28, 2026, 13:43 (UTC+9)One Chinese Signing Cert Underwrites Nine Adware Payloads
A single Chinese code-signing identity has quietly underwritten an entire adware production line. Nine distinct Windows binaries — a mix of EXEs and DLLs distributed under two different "utility" brand names — all carry the identical certificate chain: 沧州句号网络科技有限公司, chained through GlobalSign GCC R45 CodeSigning CA 2020, GlobalSign Code Signing Root R45, and GlobalSign Root CA - R3.
#code-signingabuse#adwarebundler#GlobalSigncertificate#ChinaUnicomhosting#masqueradingT1036.005#sandboxevasion#PUA-as-a-service#SaltySpiderattributionActorsSalty Spider · KuKuIOCf11 · i4 · d3 · u1MITRE11
C&CMembersJul 28, 2026, 05:37 (UTC+9)Fake uTorrent Installer Uses Malformed Signature to Hide Decade-Old Adware
A Windows installer branded as uTorrent build 331 carries an Authenticode signature that fails validation outright — VirusTotal's own signing verdict states plainly that "the digital signature of the object is malformed," pointing analysts to the decade-old Microsoft security bulletin MS13-098 that documented exactly this class of forgeable signature block.
#DealPly#InstallCore#uTorrent#adware#codesigningabuse#pay-per-install#downloadredirector#AzionCDNIOCf8 · i2 · d3 · u2MITRE34RegionsBRIndustriesSupport Services
C&CMembersJul 27, 2026, 05:36 (UTC+9)UnionPay-Named TLS Certificate Found Reused Across Three Chinese ISPs
A single TLS certificate presenting the subject line `*.unionpayintl.com is now live on three IP addresses spread across three separate Chinese autonomous systems — 61.160.230.232 on AS140293 (CHINATELECOM Jiangsu province Changzhou 5G network), 58.216.102.31 on AS134769 (ChinaNet Jiangsu Changzhou Liyang IDC network), and 218.92.141.107 on AS4134 (Chinanet).
#Ludashi#unwantedx#adware#codesigningcertificateabuse#TLScertificatereuse#PUAbundling#ChineseISPs#DigiCertActorsFIN6 · Skeleton SpiderIOCf29 · i5 · d3 · u2MITRE38IndustriesEducation & Research · Wholesale
C&CMembersJul 26, 2026, 21:42 (UTC+9)Bright Data's Own Code-Signing Cert Fronts PBot Stealer
A binary carrying Bright Data Ltd's genuine DigiCert-issued code-signing certificate — valid, unrevoked, chained straight to DigiCert Trusted Root G4 — installs itself under program paths named "Bright VPN" and "DriverHub" as net_updater32.exe. A sandbox verdict names what's actually running behind that trusted signature: PBot, classified as a credential-and-data-theft stealer. The certificate is real. The vendor is real. The proxy SDK it claims to be is real.
#BrightData#PBotstealer#code-signingabuse#masquerading#governmentsector#C2infrastructure#Let'sEncryptcertificates#DigiCertIOCf35 · i5 · d6 · u2MITRE8IndustriesGovernment
C&CMembersJul 26, 2026, 13:43 (UTC+9)Matching 89-Day Certificates Link Two 'Unrelated' Crack Sites
Two lure domains that look, on the surface, like they belong to entirely different corners of the pirated-software economy — a game-mod hub called modedapk.net and an Adobe-crack site called adobephotoshopcrack.com — are provisioning their TLS certificates on an identical clock. modedapk.net's certificate, issued by Let's Encrypt under issuer YE1, runs from 2026-07-12 to 2026-10-10. adobephotoshopcrack.com's certificate, issued under YR1, runs from 2026-06-11 to 2026-09-09.
#LummaStealer#XMRig#AsyncRAT#crack-sitemalware#Let'sEncryptcertificateabuse#Startupfolderpersistence#offsh.nlinfrastructure#commoditycrimewareIOCf13 · i2 · d2 · u11MITRE32RegionsCN
C&CMembersJul 26, 2026, 05:34 (UTC+9)A Single Chinese Certificate Has Signed Adware for 13 Straight Months
Thirteen Windows binaries submitted between April 2025 and May 2026 — spanning executables and DLLs with names like privacy_clean.exe, cclean.exe, multi_wechat.exe, and NetSentinelTray.exe — all carry the identical code-signing certificate issued to 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co.), serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert Trusted Root G4.
#Ludashi/ChinADadware#code-signingabuse#PUAdistribution#ChengduQiluTechnology#TLScertificaterecycling#ChinanetJiangsu#masqueradingT1036.005#threatfeedmisattributionActorsAPT29 · MinidionisIOCf26 · i6 · d0 · u0MITRE24IndustriesEducation & Research · Wholesale
C&CMembersJul 24, 2026, 13:39 (UTC+9)Fake .bat File Hides Packed Loader in Sprawling EU C2 Set
A single Win32 executable dressed up as docs.log.bat sits at the center of a c2-servers record otherwise padded with 57 domains and 12 IPs across a dozen European hosting providers — and the disguise is almost the whole story. Sixty of 75 engines flag the file as malicious, yet it was submitted to detection platforms exactly once, from a single source, and carries zero sandbox telemetry to explain what it actually does once it runs.
#packedloader#T1027obfuscation#persistencemechanism#Europeanhostinginfrastructure#Let'sEncryptcertificates#C2infrastructure#falsecohesion#detectionconsensusIOCf11 · i12 · d57 · u3MITRE31RegionsUSIndustriesRetail
C&CMembersJul 24, 2026, 05:40 (UTC+9)Decade-Old Dynu DDNS Pool Found Feeding Live AgentTesla C2
Eleven domains, all registered through the same free dynamic-DNS registrar, all resolving through the same nameserver block — and some of them have sat dormant since 2015. That's the picture emerging from a fresh piece of C2 infrastructure that CTX Team has been tracking since mid-June: a Dynu Systems Incorporated domain reservoir that stretches across two historical registration waves and one very recent addition, feeding a ConfuserEx-packed .NET dropper that a sandbox has tagged as…
#AgentTesla#DynudynamicDNS#C2infrastructure#ConfuserExpacker#credentialstealer#Let'sEncryptcertificatepivot#mediaandtelecomsector#domainrotationIOCf5 · i1 · d11 · u2MITRE51RegionsBD · FR · GR · HKIndustriesMedia · Telecommunications
C&CMembersJul 23, 2026, 21:42 (UTC+9)Fake Browser Installers Use Valid EV Certificates to Spread Adware
A pair of Windows installers now flagged by 30 or more security engines each didn't need packers, obfuscated loaders, or stolen certificates to get past baseline defenses — they used real ones, freshly issued to real, if newly registered, Chinese companies. One installer poses as "GptChrome," a knockoff AI-browser setup; the other impersonates JiSu (极速浏览器), a popular Chinese browser installer.
#EVcode-signingabuse#adwaredistribution#JiSubrowserinstaller#GptChromefakeinstaller#CDN-frontedinfrastructure#ChinanetZhejiang#anti-sandboxevasion#shellcompanycertificatesActorsAPT28 · StrontiumIOCf2 · i7 · d2 · u1MITRE13
C&CMembersJul 23, 2026, 13:34 (UTC+9)Certificate-Recycling Pipeline Links 12 Domains Behind Weak Detection
Twelve domains, four IP addresses, and a single executable make up this cluster — and on the surface, they look unrelated: a decade-old Vietnamese-language domain, a pair of gambling lure pages using Indonesian togel slang, a 2016-registered relic now sitting on sinkhole nameservers, and a 221MB EV-signed installer called "Rave.exe." What ties them together isn't a shared malware family or a dedicated bulletproof host.
#APT15#Ke3chang#certificateabuse#C2infrastructure#domaingenerationalgorithm#lawfirms#gamblinglures#Let'sEncryptActorsAPT15 · ROYALAPTIOCf1 · i4 · d12 · u0MITRE6IndustriesLegal Services
C&CMembersJul 23, 2026, 05:46 (UTC+9)Six Rotating Certificates Keep Chinese Adware Cluster Trusted
A batch of 19 Win32 binaries flagged under a "c2-servers" threat record shows something far more mundane, and arguably more instructive, than the record's own label suggests. Twelve of the files share one code-signing identity — 成都奇鲁科技有限公司, chained under DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 — used continuously across builds first seen from May 2025 through April 2026.
#Ludashi#ChinaAD#PUAadware#code-signingcertificaterotation#ChinaUnicom#FIN6misattribution#CDNinfrastructure#threatintellabelingActorsFIN6 · Skeleton SpiderIOCf36 · i13 · d2 · u0MITRE19
C&CMembersJul 21, 2026, 05:47 (UTC+9)Proxyware Cluster Swaps Infrastructure, Keeps Same Signed Binaries
Eighteen new domains and eight new IPs have joined a proxyware-and-stealer cluster CTX Team has been tracking since mid-July, while nineteen domains and twenty-one IPs from the prior snapshot have gone dark. That is a substantial share of the observable hosting layer turning over in a matter of days. What has not moved at all is the delivery pipeline underneath it: the same two Authenticode-signed binary families — one carrying a Bright Data Ltd.
#proxyware#stealermalware#BrightDataLtd#WEILAINETWORKTECHNOLOGY#codesigningabuse#PBot#C2infrastructure#DGAdomainsActorsCactus · Cactus Ransomware GroupIOCf114 · i22 · d52 · u13MITRE19
C&CMembersJul 20, 2026, 21:36 (UTC+9)Three Shell Companies, One Trusted Root: Adware's Signing Shuffle
Twenty binaries tied to a single Chinese-language adware and PUA toolset carry a valid "Signed" verdict from VirusTotal — but the certificates behind that verdict rotate through at least three different corporate identities, all validating through the same trusted chain: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1. 成都星汉云科科技有限公司 signs ten files. 北京创想界科技有限公司 signs seven more. 成都赤侠信息科技有限公司 signs a final two.
#adware#codesigningabuse#Ludashi#PolarWind#PCAccelerate#ChinaUnicom#Patchworkmisattribution#bundlermalwareActorsPatchwork · ChinastratsIOCf34 · i6 · d5 · u27MITRE17
C&CMembersJul 19, 2026, 21:40 (UTC+9)Signed Adware Cluster Hides Confirmed RAT Behind Chengdu Shell Certs
A 26-file cluster of Windows utility installers — branded as DllFix, WinClean, ZXStoreX and PicSnapX — is being distributed under two rotating Chinese corporate code-signing identities that both terminate in the identical certificate authority chain, and at least one binary from that signed cohort has triggered a sandbox-confirmed remote-access-trojan verdict rather than the run-of-the-mill adware payload the rest of the set carries.
#Ludashiadware#PolarWind#PubNubRAT#codesigningcertificateabuse#CDNbrandimpersonation#ChinaUnicomAS4837#Chengdushellcompanies#PatchworkmisattributionActorsPatchwork · ChinastratsIOCf26 · i16 · d15 · u16
C&CMembersJul 19, 2026, 13:38 (UTC+9)Proxyware Signing Pipeline Stays Static Despite Infrastructure Churn
Forty-seven new file hashes, twenty-seven new IP addresses and twenty-eight new domains have surfaced around a proxyware-and-stealer distribution cluster CTX Team has been tracking — yet the tradecraft underneath hasn't moved an inch. The same three code-signing chains that anchored our earlier look at this operation — Bright Data Ltd, WEILAI NETWORK TECHNOLOGY CO., LIMITED, and INNOVATIVE CONNECTING PTE.
#proxyware#PBotstealer#codesigningabuse#BrightData#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTING#certificatereuse#C2infrastructureActorsSpace Pirates · WebwormIOCf93 · i35 · d53 · u13MITRE17
C&CMembersJul 18, 2026, 21:36 (UTC+9)GoDaddy Certificate Mismatch Exposes Recycled Upatre C2 Infrastructure
A GoDaddy certificate issued in January 2024 for ebuyswap.co.uk carries a subject name of *.secure-secure.co.uk — a domain that has nothing to do with the site it secures. That single mismatch, paired with a second domain delegated to a dynamic-DNS-style nameserver pair, is the most concrete signal in a c2-servers cluster that otherwise leans on a downloader family old enough to have been retired twice over.
#Upatre#c2infrastructure#TLScertificatemismatch#dynamicDNS#GoDaddy#manufacturingsector#Australia#commoditymalwareIOCf4 · i1 · d2 · u7MITRE15RegionsAUIndustriesManufacturing
C&CMembersJul 18, 2026, 13:46 (UTC+9)Proxyware Campaign Adds Singapore CDN Cluster, Still Resigning Same Builds
Three newly observed IP addresses in Singapore — 43.169.13.123, 43.174.132.95 and 43.174.133.38 — all sit under AS139341 (ACE) and all present the identical TLS certificate serial a9573ce73eb9e83e40cd25a3a46eef4, issued by WoTrus RSA DV SSL CA 2 for the wildcard host *.cdn.myqcloud.com. It's the freshest infrastructure fingerprint to emerge from a proxyware distribution operation CTX Team has been tracking since earlier coverage of a signer cluster that kept re-signing the same builds, in a…
#proxyware#BrightData#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTING#SingaporeCDNinfrastructure#code-signingabuse#PUAmalware#AS139341ActorsAPT28 · StrontiumIOCf55 · i18 · d30 · u8MITRE16
C&CMembersJul 15, 2026, 21:46 (UTC+9)Salty Spider's KMSpico Crack-Tool Cluster Stays Frozen—And Still Works
Four KMS-activation installers circulating under the KMSpico and AutoKMS banners all carry the identical code-signing chain from an entity calling itself "@ByELDI" — a self-issued authority whose root nothing trusts, wrapped around binaries that also co-fire generic RAT-detection and anti-hook YARA rules that have nothing to do with license activation.
#SaltySpider#KMSpico#ByELDIcertificate#clipboardhijacking#cryptocurrencymining#ZettaHosting#Bulgaria#softwarepiracyActorsSalty Spider · KuKuIOCf14 · i3 · d4 · u29MITRE11IndustriesHealthcare
C&CMembersJul 14, 2026, 21:35 (UTC+9)Cloned UnionPay TLS Certificate Links 12 Chinese Carrier IPs
A single TLS certificate serial, b16a258a252d804ceb0eb5ba860f3e5, presents identically across 12 IP addresses that have no obvious business relationship — spanning China Mobile (AS56045, AS56046, AS9808), China Unicom (AS4837), multiple China Telecom provincial networks (AS142404, AS134762, AS141998, AS138169) and CT-HangZhou-IDC (AS58461).
#clonedTLScertificate#UnionPayimpersonation#code-signingabuse#adwarePUP#Ludashi#ChinaTelecomChinaUnicomChinaMobile#DigiCertmisuse#C2frontinginfrastructureActorsFIN6 · Skeleton SpiderIOCf33 · i16 · d5 · u4MITRE20IndustriesTelecommunications
C&CMembersJul 14, 2026, 05:39 (UTC+9)A Nine-Second Certificate Gap Exposes a Scripted C2 Build
Two domains on opposite sides of the top-level-domain map — deluxe.gl and geo-foundation.vg — resolve to the identical IP address, 79.124.59.146, and each received a Let's Encrypt certificate within nine seconds of the other on 2026-06-13. That kind of timing does not happen between two independent registrants. It happens when one operator, or one script, provisions both hostnames as part of the same build.
#SpringDragon#Cloudflaredomainfronting#Let'sEncryptcertificateabuse#EVcode-signingabuse#C2infrastructure#trojanmasquerade#governmentespionage#AWSrotatinginfrastructureActorsSpring Dragon · Lotus BlossomIOCf2 · i1 · d3 · u1MITRE19IndustriesGovernment
C&CMembersJul 13, 2026, 21:38 (UTC+9)Two Chinese Signing Certs Feed One Adware Pipeline, RAT Flag Emerges
Sixteen of the twenty-two files catalogued in this cluster carry "Valid" status DigiCert Trusted G4 Code Signing chains — the exact same certificate authority, issued to two different Chinese corporate identities, distributing what VirusTotal's community consistently labels as the Ludashi/PolarWind adware-PUA family. The larger cohort, twelve files signed by 北京创想界科技有限公司, spans a detection range from 5/76 up to 34/77 across a size band running from 110 KB up to 2,571 KB.
#Ludashiadware#PolarWindPUA#codesigningabuse#DigiCertcertificate#PubNubRAT#China-basedinfrastructure#CDNimpersonation#TA551misattributionActorsTA551 · ShathakIOCf22 · i68 · d5 · u2MITRE47
C&CMembersJul 12, 2026, 21:44 (UTC+9)Certificate Serial Links South African IP to GoDaddy Domain
A single TLS certificate serial number — 5ee850a60d5f88bb1442ee2acebf3310dd — is the thread that unravels this cluster. It sits on an AFRINIC-registered IP, 168.76.155.178, hosted under ASLINE LIMITED (AS137951) in South Africa, and it sits, identically, on guomcc.com, a domain registered through GoDaddy.com, LLC back in July 2024.
#C2infrastructure#certificatereuse#Let'sEncryptabuse#phishingdomains#AdvancedIPScanner#hostingproviderabuse#brandimpersonation#trust-chainabuseActorsLockbit GangIOCf2 · i29 · d32 · u1MITRE8
C&CMembersJul 12, 2026, 13:44 (UTC+9)PacketStream Installer Trio Shares Expired Cert, Trips GhostSocks Rule
Three binaries carrying the PacketStream brand — an installer, a launcher, and a client — all share one code-signing certificate that expired more than a year before the files were still circulating with it attached. The certificate, issued to "PacketStream Inc" and chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, carries serial number 08 A1 E1 05 55 6E 22 8D 46 FE D7 72 3C 52 19 1E and a signing timestamp of 07:57 AM on May 2, 2024 — identical across all three files…
#PacketStream#GhostSocks#code-signingcertificateabuse#SOCKS5proxyware#KoreaTelecomAS4766#adwareandPUA#ageddomainreuse#APT28misattributionActorsAPT28 · StrontiumIOCf3 · i13 · d5 · u0MITRE28
C&CMembersJul 12, 2026, 05:45 (UTC+9)One DigiCert Root, Four Shell Firms: Inside a Chinese Adware Signing Ring
A single DigiCert code-signing root has quietly underwritten twenty different Chinese PC-optimizer and "app store" installers over roughly three years — but the signer name attached to that root has changed four times. 成都奇鲁科技有限公司, 北京创想界科技有限公司, 成都星汉云科科技有限公司, and a now-expired Chengdu Qilu Technology Co. Ltd. certificate all chain up to either "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1" or its SHA2 predecessor, signing installer chrome, uninstallers, and helper DLLs that…
#Ludashiadware#code-signingabuse#DigiCertcertificates#PubNubRAT#PUAdistribution#ChinaCDNinfrastructure#PatchworkAPTattribution#xhyktech.comActorsPatchwork · ChinastratsIOCf33 · i2 · d5 · u28
C&CMembersJul 11, 2026, 21:37 (UTC+9)Two Dead Certificates Still Signing Live VPN Malware
Two unrelated shell companies — one issued an EV code-signing certificate by GlobalSign, the other an OV certificate by DigiCert — are each vouching for a trio of VPN-branded Windows binaries whose leaf certificates VirusTotal now flags as "not time valid." That should mean nothing runs. Instead, both cohorts keep circulating: a "WireVPN" loader-and-DLL set signed under WEILAI NETWORK TECHNOLOGY CO., LIMITED racks up 14 to 29 flags out of 74-75 engines, while a "VPNMaster" trio signed under…
#code-signingabuse#WireVPN#VPNMaster#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTINGPTE.LIMITED#PUAbundler#proxyware#trust-controlsubversionActorsSpace Pirates · WebwormIOCf37 · i21 · d87 · u27MITRE18
C&CMembersJul 10, 2026, 19:36 (UTC+9)One DigiCert Certificate Signed 13 Chinese Adware Builds for 18 Months
The most durable artifact in this dataset isn't a zero-day or a novel loader — it's a single DigiCert-issued code-signing certificate that has quietly signed thirteen different Win32 binaries over eighteen months, from November 2024 through May 2026. The signer of record is 成都奇鲁科技有限公司, and the certificate — serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert Trusted Root G4 — has stayed valid and in…
#code-signingcertificateabuse#adware/PUAdistribution#China#TLScertificatespoofing#UnionPayimpersonation#defenseevasion#DigiCert#config-deliveryinfrastructureActorsFIN6 · Skeleton SpiderIOCf42 · i21 · d5 · u10MITRE22IndustriesTelecommunications
C&CMembersJul 10, 2026, 09:03 (UTC+9)Three Valid Chinese Code-Signing Certs Push Adware Past AV, Sandboxes
Three legitimately issued DigiCert code-signing certificates — bearing the corporate names Shanghai Oriental Webcasting Co. Ltd., Shenzhen Kaixin Kangaroo Technology Co., Ltd., and Shanghai 2345 Mobile Technology Co., Ltd. — sit atop a wave of Chinese consumer-software installers that up to 47 of 77 antivirus engines now flag as adware, even as the same binaries clear behavioral sandboxes as harmless.
#code-signingcertificateabuse#adware#PUA#ChineseCDNimpersonation#HuaweiAppGalleryspoofing#C2infrastructure#DigiCert#sandboxevasionActorsSalty Spider · KuKuIOCf25 · i11 · d1 · u1MITRE32
C&CMembersJul 10, 2026, 08:48 (UTC+9)Self-Signed 'malware.com' Cert Ties Two Domains to One Host
Two subdomains of one 2018-registered domain — update.buffernavpose.com and errors.buffernavpose.com — terminate in an identical self-signed TLS certificate whose subject and issuer both read literally "*.malware.com," issued under the stock OpenSSL demo organization name "Internet Widgits Pty Ltd." Both hostnames resolve to the same address, 34.209.195.255, and both sit on a domain registered through Dynadot Inc on 2018-05-12 and still being updated as recently as 2026-04-16.
#APT28#shlayer#self-signedcertificate#update.jsonbeacon#PUPadware#Dynadotdomain#energysector#C2infrastructureActorsAPT28 · StrontiumIOCf2 · i0 · d2 · u36MITRE15IndustriesEnergy
C&CMembersJul 10, 2026, 04:33 (UTC+9)Debug-Path YARA Rule Unmasks Prometei Botnet Behind OilRig Label
Two files land in this cluster carrying almost nothing in common on paper. One is tagged by commercial engines as trojan.prometei/bjsg; the other as trojan.gdvw/leonem. Their import hashes differ entirely, and nothing in their surface metadata suggests a shared origin. Yet both — 39b1042a5b02f3925141733c0f78b64f9fae71a37041c6acc9a9a4e70723a0f1 and ea8cde21792543d7e55dd9a2a894c3cd4fc4fabaeab20ba689b84416c20a6e37 — fire the same crowdsourced YARA rule, Prometei_PDB, a signature built specifically…
#Prometeibotnet#OilRig#APT34#SSHRDPbruteforce#self-propagatingmalware#YARAdetection#CAPESandbox#masqueradingActorsOilRig · APT34IOCf4 · i1 · d0 · u0MITRE9IndustriesTelecommunications
C&CMembersJul 9, 2026, 18:51 (UTC+9)Three-IP Hosting Block Masks KuCoin Fake and Wallet-Stealer Kit
Three IP addresses — 62.60.226.159, 196.251.107.104, and 196.251.107.130 — sit on a single small hosting block registered to Femo It Solutions Limited under AS214351, and two of them are dressed in freshly minted TLS certificates that have nothing to do with each other's cover story. One serves a Let's Encrypt certificate for "kucoin.sh," complete with subject alternative names for security.kucoin.sh and www.kucoin.sh — a crypto-exchange lookalike.
#KuCoinimpersonation#clipboardhijacker#Exoduswallettheft#AS214351#FemoITSolutions#Let'sEncryptcertificateabuse#commoditystealer#PHPC2panelIOCf32 · i3 · d0 · u9MITRE56RegionsDE · VNIndustriesTelecommunications
C&CMembersJul 8, 2026, 18:49 (UTC+9)One Reflective Loader, Three Antivirus Verdicts: A Single Kit Unmasked
Antivirus engines looked at three Windows binaries and returned three different answers: stealc/marte, clipbanker/tedy, mikey/bank. A closer read of the code underneath tells a different story. All three — a 10.5MB file masquerading as "EmailCheckerPro 2.0.exe", a 253KB "WindowsHost.exe," and a 333KB dropper staged under %APPDATA% — co-fire the same two YARA rules, ReflectiveLoader and INDICATOR_SUSPICIOUS_ReflectiveLoader, tripwires that flag reflective DLL injection artifacts rather than any…
#Stealcv2#ClipBanker#Amadey#reflectiveDLLinjection#CMSTPUACbypass#BYOVD#FemoITSolutions#domain-lessC2infrastructureIOCf11 · i4 · d0 · u10MITRE20RegionsHK
C&CMembersJul 8, 2026, 02:44 (UTC+9)Five Malware Families, One Shared Diamotrix C2 Panel
Eight new binaries entered the same tracked cluster this week, and on paper they look like five unrelated infections: a ClipBanker variant, a second ClipBanker variant, a third ClipBanker variant, a StealC-labelled stealer, a PowerLoader-tagged loader, and a file flagged as Rhadamanthys whose only sandbox verdict instead calls it Formbook. Static antivirus labels alone would read this as a grab-bag of commodity crimeware.
#StealCv2#ClipBanker#PowerLoader#Rhadamanthys#Diamotrix#reflectiveDLLinjection#command-and-controlinfrastructure#malware-as-a-serviceIOCf8 · i4 · d0 · u8MITRE48RegionsES