C&CMembersSep 21, 2026, 22:29 (UTC+9)Two Shell Firms, One DigiCert Root: Adware's Signing Trick Repeats
AloneTrayServer.exe and MLPrivacy.exe — two installers newly added to a long-running Chinese adware-distribution cluster — both carry valid, chained code-signing certificates issued to a company calling itself 成都星汉云科科技有限公司. That in itself would be unremarkable. What makes it worth a second look is that this is now the second shell identity CTX Team has traced back to the exact same intermediate certificate authority — DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 — after an earlier…
#code-signingabuse#shellcompanies#DigiCert#adware#Ludashi#T1553.002#sideloading#China-basedinfrastructureIOCf9 · i3 · d4 · u1MITRE45
C&CPublicSep 21, 2026, 06:50 (UTC+9)A Two-Tier Certificate Strategy Behind a Freshly Rotating C2 Cluster
Four IP addresses and three domains now tracked under a single command-and-control cluster show something that rarely shows up this cleanly in raw infrastructure data: two entirely different levels of operational care, running side by side on the same campaign. On one tier, listener IPs are still wearing the certificates they shipped with — an OpenSSL install default, a Chinese vendor's untouched template — the kind of TLS hygiene nobody bothers to fix on infrastructure meant to be thrown away.
#command-and-controlinfrastructure#TLScertificatehygiene#wildcardcertificates#dynamicDNS#DGAdomains#unattributedthreatcluster#certificatetransparency#networkinfrastructureanalysisIOCf0 · i4 · d3 · u0MITRE10IndustriesContainers & Packaging
C&CPublicSep 20, 2026, 22:49 (UTC+9)Emotet 'C2 Servers' Entry Bundles 3 Unrelated IPs, No Shared Fingerprint
A feed entry logged at 00:03 UTC on September 20 groups nine indicators under the category "c2-servers" — a single Emotet loader DLL and three IP addresses spread across Malaysia, Ghana and South Korea. The label implies a working command-and-control triangle behind a live banking-trojan campaign. The evidence inside the record says something closer to the opposite: none of the three IPs share an autonomous system, a certificate, or a registrant record with each other or with the file, and two…
#Emotet#C2infrastructure#bankingtrojan#threatintelligencefeeds#certificatestaleness#Malaysia#Ghana#SouthKoreaIOCf6 · i3 · d0 · u6RegionsUSIndustriesRetail
C&CMembersSep 20, 2026, 14:37 (UTC+9)A Hidden Macrosheet Reopens Emotet's Front Door
A spreadsheet flagged as trojan.abracadabra/emotet, submitted for scanning barely a day before this review and already caught by 42 of 75 engines, carries an Excel4 macro built to fire the moment the file opens — and the macro logic itself sits inside a sheet the workbook keeps hidden from anyone who opens it in Excel. Two named detections establish this precisely: the YARA rule `SUSP_Excel4Macro_AutoOpen matches the auto-executing macro trigger, and Microsoft_Excel_Hidden_Macrosheet` catches…
#Emotet#TA542#Excel4macro#hiddenmacrosheet#DridexJA3fingerprint#Zenpakloader#retailsector#crimewareinfrastructureActorsEmotet Group · TA542IOCf5 · i3 · d1 · u6RegionsUSIndustriesRetail
C&CMembersSep 20, 2026, 06:37 (UTC+9)Adware Operator Recycles Qihoo, Alibaba, UnionPay TLS Certs on Carrier IPs
Four subdomains under a single Chinese apex — adblock.yunkeit.com, cdn-ali-v3.yunkeit.com, stat.yunkeit.com and upgrade.yunkeit.com — were all registered on the same day, 2025-09-11, through the Hichina registrar (grs-whois.hichina.com, nameservers DNS23/24.HICHINA.COM). Three of the four resolve to the identical A-record, 47.94.14.179, and the fourth, cdn-ali-v3.yunkeit.com, fans out across an eight-address block (180.163.147.83 through .90) behind a CNAME to w.kunluncan.com.
#yunkeit.com#codesigningabuse#TLScertificaterecycling#ChinaMobile#adwaredistribution#Ludashi#DLLside-loading#PUAbundlerIOCf8 · i11 · d4 · u3MITRE36
C&CMembersSep 19, 2026, 06:33 (UTC+9)New Iranian IP Completes Matched Amadey C2 Pair on AS44208
A new IP address surfaced in the latest sweep of this Amadey-and-RedLine crimeware cluster, and it doesn't open a new front — it closes a loop. 176.46.152.47 sits one address away from 176.46.152.46, both inside the same /22 block registered to Farahoosh Dena PLC under AS44208 in Iran, and both now confirmed serving the identical panel path, `/diamo/data.php, alongside a shared payload filename, /zx.exe.
#Amadey#RedLineStealer#ClipBanker#C2infrastructure#Iran#FarahooshDenaPLC#forgedcodesigning#crimewareIOCf14 · i3 · d0 · u20MITRE55RegionsUSIndustriesRetail
C&CMembersSep 18, 2026, 14:27 (UTC+9)Four Disposable-Infrastructure Playbooks Share One Sharktech Backbone
A c2-servers indicator set logged by CTX Team's telemetry on 18 September carries not a single malicious file — no hash, no PE, no sandbox verdict anywhere in it. What it does carry is five IPs and eight domains, and inside that narrow footprint sit four distinct, professionally executed infrastructure playbooks running side by side: a single Let's Encrypt certificate stretched across eight numeric look-alike domains, a same-day-registered Cloudflare-fronted subdomain pair, a same-day…
#Sharktechhosting#Cloudflarefronting#fast-fluxDNS#dynamicDNSrotation#Let'sEncryptcertificatereuse#bulletproofhosting#phishinginfrastructure#containersandpackagingsectorIOCf0 · i5 · d8 · u0MITRE14IndustriesContainers & Packaging
C&CMembersSep 16, 2026, 22:53 (UTC+9)Shared Panel Path Ties Five Rebranded Stealers to One C2 Backend
Eleven Windows payloads carrying five different VirusTotal threat labels — Amadey/Lumma, Stealc, ClipBanker/Cerbu, Kasidet/Fragtor, and Barys — all check in with the same small cluster of IP addresses using a verbatim-identical control-panel path. That's not a coincidence of naming; it's a shared backend wearing five different masks, and it's the detail that makes this cluster worth a second look rather than five separate incident tickets. The path reuse is concrete and traceable.
#Stealc#Amadey#Lumma#ClipBanker#Kasidet#Barys#AS214351#commoditymalwareC2IOCf13 · i5 · d2 · u15MITRE60RegionsBA
C&CMembersSep 16, 2026, 14:31 (UTC+9)Bright Data-Signed Proxy SDK Joins Signed VPN-Trojan Pipeline
Two freshly signed executables — a proxy updater called net_updater.exe and a companion labelled idle_report.exe (2b7c3cdca1fd951c…), both carrying a Bright Data Ltd certificate and both first submitted just seventeen days before this review — have surfaced inside a signed-installer distribution pipeline CTX Team has continued to track.
#WireVPN#VPNMaster#BrightData#LuminatiproxySDK#code-signingabuse#sandboxevasion#residentialproxymonetization#signed-installerdistributionActorsCactus · Cactus Ransomware GroupIOCf17 · i14 · d30 · u9MITRE19
C&CMembersSep 15, 2026, 14:49 (UTC+9)Signed and Trusted: Two Malware Families Ride Valid Certs
Four executables signed with a fully valid Bright Data Ltd certificate — the kind of code-signing chain that is supposed to reassure a user they are installing legitimate software — carry threat labels ranging from hacktool and PUA to adware and downloader, and one of them was flagged outright by a sandbox as a stealer. The file, an 11.5MB installer named net_updater.exe (909f62b450…), returned a malicious verdict with the classification "STEALER" and the family name "PBot," despite presenting…
#BrightDataSDK#PBotstealer#wirevpn/jumpertrojan#code-signingabuse#residentialproxyabuse#revokedEVcertificate#templatedTLSinfrastructure#VPNtrojandistributionActorsCactus · Cactus Ransomware GroupIOCf21 · i19 · d30 · u9MITRE18
C&CMembersSep 13, 2026, 22:30 (UTC+9)A Redirect Node With No Name: Certificate Cycling Masks a 2014 Dropper
A domain buried inside a routine C2-infrastructure record — baktus.kilu.de — is not serving its own website. Query it over TLS and the certificate that comes back carries the subject name redirect.subdomain.com, a string that points nowhere near the domain a browser actually requested. That mismatch is the clearest single artefact in this record: it marks the node as a relay hop inside a shared hosting fabric, not an independent site with its own identity.
#invoiceluremalware#Let'sEncryptcertificatecycling#wildcardSANabuse#redirectorinfrastructure#overlaydataPE#billingfraudphishing#C2domainrotation#unattributedclusterIOCf10 · i3 · d16 · u7MITRE23RegionsGB · ROIndustriesTechnology
C&CMembersSep 13, 2026, 15:00 (UTC+9)Decade-Old GameOver Zeus DGA Signature Still Catching Live Malware
Ten Snort and Emerging Threats alerts fired against a 13-kilobyte Windows executable disguised as a courier tracking notice — five of them the exact same rule, "MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected." That rule was written for GameOver Zeus, the peer-to-peer variant of the Zeus banking trojan that law enforcement spent years trying to dismantle starting in 2014.
#Zeus#ZBot#GameOverZeus#domaingenerationalgorithm#Let'sEncryptcertificates#PEiDpacker#commandandcontrol#credentialtheftIOCf5 · i2 · d20 · u6MITRE16RegionsRO
C&CMembersSep 13, 2026, 06:52 (UTC+9)Shared TLS Certificate Links Hong Kong IP to Front Domain in C2 Set
Nine domains and four IP addresses tagged as command-and-control infrastructure share almost nothing in common — different registrars, different countries, different certificate authorities — except for one pairing that stands out precisely because it shouldn't exist by coincidence. The IP address 45.154.14.190, registered to MOACK.Co.LTD under AS 138195 in Hong Kong, presents a TLS certificate whose subject and subject-alternative-name field read "anfangshen.com" and "*.anfangshen.com." The…
#commandandcontrolinfrastructure#TLScertificateabuse#Let'sEncrypt#BrightData#PBotstealer#Cactusransomwaregroup#phishingdomains#codesigningabuseActorsCactus · Cactus Ransomware GroupIOCf1 · i4 · d9 · u1MITRE7IndustriesManufacturing · Telecommunications
C&CMembersSep 11, 2026, 22:51 (UTC+9)Twenty Throwaway .xyz Domains Funnel Into One Kronos Panel Path
Twenty domains in this record — every one an algorithmically-generated string of consonant clusters under the .xyz top-level domain — resolve, wherever resolution data survives, to the identical checkout path /kronos/connect.php. That is not a coincidence of naming; it is the fingerprint of a single command-and-control panel template stamped across disposable infrastructure rather than the work product of twenty independent operators standing up their own C2.
#Kronosbankingtrojan#C2infrastructure#domaingenerationalgorithm#packed.NETloader#.xyzdomains#WHOISobfuscation#financiallymotivatedcybercrime#anti-analysistechniquesIOCf3 · i0 · d22 · u40MITRE31RegionsCH · JOIndustriesSupport Services
C&CMembersSep 10, 2026, 22:28 (UTC+9)Shared Certificates Tie Decade-Spanning Domains to Proxyware Cluster
Five domains with nothing obviously in common — a fitness-therapy site, a Korean-registered shell, a martial-arts studio, a decade-old Chinese-registered parking page, and a fresh mobile subdomain — picked up new TLS leaf certificates from Google Trust Services within the same seven-week window in mid-2026. tswlmy.com has been registered since April 2013; fxlvpaiguan.com was registered on 2026-07-31, barely a month before the record was compiled.
#WireVPN#VPNMaster#BrightData#Zenlayer#proxyware#code-signingabuse#certificateprovisioning#PUAloadersActorsCactus · Cactus Ransomware GroupIOCf50 · i7 · d13 · u4MITRE12
C&CMembersSep 10, 2026, 14:43 (UTC+9)Amadey Malware Wears Expired Microsoft Certificate, Skips DNS
Two payloads dropped in the same late-July 2025 build window — a 2,582 KB Windows executable and a 6,338 KB 64-bit DLL — carry an identical Microsoft code-signing chain, down to the leaf certificate's serial number, and both fail signature verification the moment a scanner actually checks the math. The certificate reads "Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010," a fully-formed three-tier chain that would pass a glance at a properties…
#Amadey#RedLineStealer#LummaStealer#codesigningforgery#clipboardhijacking#C2infrastructure#commoditycrimeware#DNS-lessC2IOCf9 · i2 · d0 · u14MITRE43RegionsVN
C&CMembersSep 10, 2026, 06:48 (UTC+9)Shared Loader Code Links Five 'Unrelated' Malware Families to One C2
Ten files, five different antivirus family labels, and one code-level fingerprint that should not be there. A clipboard-hijacking banker compiled as a 251KB Windows executable and a bazaar-style loader shipped as a 109KB DLL — tools that vendor engines classify as entirely separate malware — both fire the identical YARA rule pair `INDICATOR_SUSPICIOUS_ReflectiveLoader and ReflectiveLoader.
#StealC#BazarLoader#ClipBanker#Amadey#reflectiveDLLinjection#bare-IPC2#AS214351#FemoITSolutionsIOCf10 · i3 · d0 · u8MITRE48
C&CMembersSep 9, 2026, 22:36 (UTC+9)Valid Bright Data Certificate Signs a Sandboxed PBot Stealer
A residential-proxy SDK carrying a currently valid Bright Data Ltd code-signing certificate has been sandboxed with a malicious verdict naming the stealer family PBot — the freshest and most unsettling signal in a ten-file set that otherwise reads like ordinary VPN and proxy bloatware. Two other toolchains in the same batch ride certificates that have already been revoked or expired, yet neither produces a cleaner behavioural outcome than the one still in good standing.
#BrightDataSDK#PBotstealer#residentialproxyabuse#WEILAIGlobalSignEVcertificate#VPNMasterbundler#code-signingcertificateabuse#PUAadwareeconomy#trojanizedinstallerIOCf21 · i8 · d12 · u0MITRE21
C&CMembersSep 8, 2026, 22:31 (UTC+9)Fake Alibaba, UnionPay Certificates Mask C2 on China Mobile IPs
A TLS certificate now circulating across five carrier-grade Chinese IP addresses lists its subject organization as "Alibaba (China) Technology Co., Ltd." — a real corporate name borrowed for infrastructure that has nothing to do with the company. The certificate, serial 6696262f452fcf46b79266a8, carries the common name *.certfallback.com and was issued by GlobalSign's GCC R46 OV TLS CA 2025, an organization-validated authority that is supposed to confirm the entity behind a certificate before…
#Alibabaimpersonation#UnionPayimpersonation#ChinaMobile#TLScertificatespoofing#C2infrastructure#yunkeit.com#GlobalSignOVcertificate#carrierIPabuseIOCf3 · i6 · d3 · u1MITRE37
C&CMembersSep 8, 2026, 06:50 (UTC+9)No Domain, No Problem: Amadey Loader Cluster Skips DNS Entirely
Six files and three IP addresses make up this record, and not one of them ever needed a hostname. Every network indicator in the set — thirteen URLs in total — resolves to a bare dotted-quad address rather than a domain, a detail confirmed by the indicator catalog itself: the domains table carries a header row and nothing beneath it. That is the most concrete signal in this campaign, and it is not incidental.
#Amadey#Stealc#Lumma#MicroClip#IP-basedC2#DNSevasion#OmegatechLTD#bulletproofhostingActorsTransparent Tribe · Copper FieldstoneIOCf6 · i3 · d0 · u13MITRE34RegionsNG
C&CMembersSep 7, 2026, 22:38 (UTC+9)Revoked EV Cert and Live Bright Data Signature Both Weaponized
Three separate builds of a fake VPN client — upWire.exe, wire.exe and wire.dll — carry the exact same EV code-signing certificate from a company called WEILAI NETWORK TECHNOLOGY CO., LIMITED, and every one of them was signed and distributed well after VirusTotal's own signature chain marked that certificate "not time valid" and its trust "revoked." That is not a one-off scan artifact.
#code-signingabuse#revokedcertificate#BrightDataSDK#PBotstealer#fakeVPNinstaller#WEILAINETWORKTECHNOLOGY#signed-binarytrustabuse#residentialproxySDKActorsSpace Pirates · WebwormIOCf10 · i4 · d3 · u1MITRE19IndustriesGovernment
C&CPublicSep 7, 2026, 14:30 (UTC+9)Sandbox Verdict 'EVADER': RFQ Downloader's Debugger Checks and Stalls
A JavaScript downloader dressed as a routine purchase-order email doesn't just evade detection by accident — in this case, a sandbox measured the evasion and gave it a name. Zenbox returned a 100%-confidence verdict of "MALWARE/EVADER" against a script masquerading as "Anika RFQ NEW ORDER V01370P25080002.js" (a670ca27…), flagging behaviour that checks whether a debugger is attached and deliberately stalls execution for long periods before doing anything else.
#EVADERsandboxverdict#RFQphishinglure#JavaScriptdownloader#trimnt.comC2#catbox.moeabuse#sagentmalware#Let'sEncryptcertificateabuse#detonation-delayevasionIOCf13 · i2 · d1 · u1RegionsAE · AT · AU · AZIndustriesArts & Entertainment · Automotive · Construction
C&CMembersSep 6, 2026, 14:28 (UTC+9)Fake VPN Installers Share Packer Fingerprint, Revoked Certificate Reuse
A metadata marker meant to track Adobe image assets — the kind of thing that normally shows up in a PDF or a photo editor — turns up instead inside three Windows installers that have nothing else in common on paper. One poses as a Viber setup file. Two are builds of Bright Data's legitimate residential-proxy SDK, sold commercially as net_updater.exe.
#WireVPN#BrightDataSDK#PBotstealer#revokedEVcertificate#self-signedTLScertificate#code-signingabuse#C2infrastructure#ZenlayerBytedancehostingActorsCactus · Cactus Ransomware GroupIOCf36 · i8 · d12 · u2MITRE16
C&CMembersSep 6, 2026, 06:41 (UTC+9)Five-Year-Old Phorpiex Banker Still Fools Two of Six Sandboxes
A Win32 executable built in May 2021 is still checking in against the same command-and-control panel it has used for years, and it is still winning against two of the six sandboxes that tried to detonate it. The file — 100KB, unsigned, carrying the threat label trojan.phorpiex/clipbanker (552ac091…9e17) — has been resubmitted 46 times from 37 unique sources, with a submission as recent as 2026-08-22 sitting on top of a compile timestamp from 2021-05-07.
#Phorpiex#ClipBanker#clipboardhijacking#commandandcontrol#sandboxevasion#cryptocurrencytheft#constructionsector#ToronionserviceIOCf3 · i1 · d1 · u7MITRE34RegionsBO · KZ · MXIndustriesConstruction · Technology
C&CMembersSep 5, 2026, 22:27 (UTC+9)Fake VPN Installer, IR-Aware Beacon, Forged Signature Tie to One Server
A fake VPN installer that a leading sandbox rated 97% "clean," a reverse-shell beacon built to notice when incident responders are watching, and a 6-megabyte trojan that dresses itself in a code signature no root authority will vouch for — three unrelated builds, no shared imphash, no shared signer, converging on a single certificate-linked server.
#APT28#trojanizedVPNinstaller#reverse-shellbeacon#codesigningabuse#Let'sEncryptcertificate#C2infrastructure#Netherlandshosting#IDSdetectionActorsAPT28 · StrontiumIOCf34 · i1 · d1 · u2RegionsCH · JO · TWIndustriesFood & Beverages · Government · Support Services
C&CMembersSep 3, 2026, 14:32 (UTC+9)Disposable Certs and VPS Templates Tie Together a VPN-Trojan/Stealer Web
Three IP addresses in a single Zenlayer /21 block in the Philippines — 156.59.113.131, 156.59.113.132, and 156.59.113.134 — are all presenting the exact same self-signed TLS certificate, serial 1acf3e37b37910d932ea64e6bb27615d6484c07d, valid from March 2024 clear through March 2034. None of the three shows any VirusTotal detections (0/91 across the board), and none carries a hostname behind the certificate — the issuer and subject fields both read simply "NONE." That absence of a domain layer…
#Zenlayer#self-signedcertificate#BrightData#PBotstealer#WEILAINETWORKTECHNOLOGY#codesigningabuse#Philippinesinfrastructure#trojanizedVPNinstallerIOCf30 · i6 · d14 · u5MITRE9
C&CMembersSep 2, 2026, 23:06 (UTC+9)Bot Panel's Command Menu Exposed in Plain URL Parameters
A command-and-control server rarely tells a researcher what it can do before it is even queried, but the PHP panel sitting behind 5.175.209.151 does exactly that. Six URLs observed against the IP all funnel through the same script, /ft/si.php, and the query strings read like an operator's own feature list rather than obfuscated traffic: a listing function, a version check, a download trigger, a shell-execution flag, and a distributed-denial-of-service tasking flag, all addressed to a single bot…
#GamaredonGroup#wavipegtrojan#PHPbotpanel#DDoStasking#Microsoftmasquerade#RIPENCCGermany#imphashcluster#C2infrastructureActorsGamaredon Group · CTIGIOCf8 · i1 · d0 · u6MITRE27RegionsUA
C&CMembersSep 2, 2026, 06:42 (UTC+9)Decade-Old Locky-Lineage Loader Rides New Four-Nation C2 Panel Grid
A command-and-control backbone built from eight bare-IP endpoints spread across four unrelated hosting networks in Russia, Estonia and France — every single one answering on the identical /main.php path — has surfaced attached to a loader that first appeared on file-scanning services back in 2016. The infrastructure is the story here: none of the four autonomous systems recur elsewhere in the indicator set, no certificate or registrar links any of the eight domains that sit behind them, and yet…
#Rtm#CryptOne#Locky#Cerber#Tinba#C2infrastructure#DGAdomains#loadermalwareActorsRtmIOCf1 · i4 · d8 · u16MITRE10RegionsCH · JOIndustriesGovernment · Support Services
C&CMembersSep 1, 2026, 22:41 (UTC+9)PANMAP Dropper Fakes Microsoft Branding, C2 Cert Predates Domain
A Win32 dropper carrying the internal name PANMAP and presenting itself as PANMAP.DLL — complete with a product string reading "Microsoft® Windows® Operating System" and a Microsoft copyright line — ships with no valid code signature at all; signature validation on the binary fails outright. That single contradiction, a file dressed head-to-toe in Microsoft branding while carrying zero cryptographic proof of Microsoft origin, is the cleanest piece of tradecraft in this record, and it anchors a…
#PANMAPdropper#masquerading#Smokeloader#Tinba#self-signedcertificate#C2domain#SmokySpider#stagedpayloadActorsSmoky SpiderIOCf1 · i0 · d1 · u1MITRE21RegionsCH · JOIndustriesSupport Services
C&CMembersAug 31, 2026, 15:07 (UTC+9)Three-Year-Old njRAT Builder Fingerprint Resurfaces in 2026 Wave
Five .NET executables tracked in this reporting cycle, first surfacing as early as May 2023 and as recently as April 2026, share a single import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — and a universal .NET Reactor packing signature, even though VirusTotal's own classifiers split them across three different label aliases: bladabindi, variadic, and cdmip. That split is cosmetic.
#njRAT#Bladabindi#commodityRAT#C2infrastructure#PaaSabuse#imphashtracking#UACbypass#LazarusGroupattributionActorsLazarus Group · Hastati GroupIOCf7 · i1 · d6 · u4MITRE33RegionsUS
C&CMembersAug 30, 2026, 14:45 (UTC+9)One Wildcard Certificate Links Five China Unicom IPs Across Four Subnets
Five IP addresses sitting on four separate subnets inside China Unicom's core network all answer HTTPS requests with the exact same TLS certificate — serial 6696262f452fcf46b79266a8, issued by GlobalSign GCC R46 OV TLS CA 2025, carrying the subject organisation "Alibaba (China) Technology Co., Ltd." and a wildcard subject name of *.certfallback.com. That is not a coincidence of shared hosting; it is one certificate identity deliberately deployed across a diversified physical footprint.
#ChinaUnicomAS4837#TLScertificateabuse#C2infrastructure#codesigningabuse#HaoZip#2345adware#Salityattribution#fallbackhostingActorsSalty Spider · KuKuIOCf5 · i5 · d1 · u1MITRE16
C&CMembersAug 29, 2026, 00:50 (UTC+9)83 'Suppobox' Domains Trace Back to a Handful of Shared Hosts
Eighty-three lookalike ".net" domains sit inside a single threat-feed category tagged "suppobox," but the interesting story here is not a payload — it is how the hosting layer beneath those domains was built. Stripped of their two-word dictionary names (gentlemanprobable, waterbicycle, experiencewithout), the domains resolve down to a handful of shared IPs, recycled nameserver pairs, and certificates that were either batch-issued or borrowed outright from unrelated infrastructure.
#suppobox#C2infrastructure#domaingenerationalgorithm#certificateabuse#Dynadot#retailsector#UnitedStates#sharedhostingIOCf3 · i0 · d83 · u7MITRE25RegionsUSIndustriesRetail
C&CMembersAug 28, 2026, 14:49 (UTC+9)Decade-Old Firefox Impersonator Resurfaces in 2026 C2 Feed
A 139-kilobyte Windows executable that dresses itself up as Firefox 40.0.3 — spoofing the product name, internal name and copyright string of Mozilla's own build metadata while carrying no digital signature at all — has surfaced inside a command-and-control indicator set first logged on 2026-02-05 and still being tracked through 2026-08-28. The file itself is nothing new: its earliest submission dates to 2015-12-10, a full decade before the rest of this record's sighting window opens.
#waledac#Firefoxspoofing#processinjection#malwareloader#C2infrastructure#unsignedexecutable#BulgariaISP#Let'sEncryptcertificateIOCf1 · i8 · d0 · u2MITRE14RegionsUSIndustriesRetail
C&CMembersAug 27, 2026, 06:30 (UTC+9)2006 MyDoom Worm Resurfaces Tagged as Lazarus Espionage Tool
A file that has been circulating since the summer of 2006 just resurfaced inside a threat feed carrying a severity score of 82, a confidence score of 85, and an attribution line naming Lazarus Group — the North Korea-aligned operation with roughly twenty tracked aliases. The artefact behind that label is not a bespoke implant.
#LazarusGroup#MyDoom#agentwdcr#Tofseebotnet#JA3fingerprint#sandboxevasion#threatintelaggregation#IncapsulaCDNActorsLazarus Group · Hastati GroupIOCf35 · i7 · d6 · u0
C&CMembersAug 20, 2026, 22:46 (UTC+9)A Certificate for Every Stage: How DustSquad Weaponized Three Trust Systems
Two adware installers signed under a code-signing certificate that was later revoked. A VPN-branded credential stealer signed under a Microsoft-verified chain whose leaf certificate was valid for exactly three days. A pair of command-and-control nodes on two different continents, each wearing a TLS certificate cloned to look like Akamai or Alibaba Cloud.
#DustSquad#APT-C-34#NomadicOctopus#PureLogStealer#code-signingcertificateabuse#TLScertificatecloning#Akamaispoofing#adwarebundlersActorsDustSquad · APTC34IOCf3 · i8 · d7 · u0IndustriesNon-Profit
C&CMembersAug 20, 2026, 06:42 (UTC+9)Shared TLS Certificate Ties Two China Telecom ASNs to One CDN Edge
The most interesting fact in this catalog isn't a file — it's a TLS certificate. Two IP addresses sitting on different China Telecom autonomous systems, 113.96.132.210 (AS4134, Chinanet) and a newly catalogued 119.147.118.106 (AS134763, CHINANET Guangdong province network), terminate the exact same certificate: serial b234dba9d0c0f44f93cd5fdc51fcfa4, issued by DigiCert Basic OV G2 TLS CN RSA4096 SHA256 2022 CA1, subject default.chinanetcenter.com.
#ShanghaiOrientalWebcasting#WanNengWBInput#Shanghai2345MobileTechnology#ChinaNetCenterCDN#code-signingabuse#adware#sandboxevasion#ChinaTelecominfrastructureActorsGroup123 · Venus 121IOCf16 · i4 · d0 · u0MITRE28
C&CMembersAug 19, 2026, 06:51 (UTC+9)Signed 2345HomePage Adware Installer Splits AV Detection in Two
A validly signed homepage-hijacking installer from Shanghai 2345 Mobile Technology Co., Ltd. is drawing detections from 31 of 77 antivirus engines, yet neither of the two sandboxes that detonated the file called it malicious. That split — a firm static-engine consensus sitting on top of a clean dynamic verdict — is the most concrete new finding to surface in this update to a Chinese command-and-control cluster carrying a phorpiex family tag and a financial-gain motivation.
#phorpiex#2345MobileTechnology#code-signingabuse#adware/PUA#ChinaTelecom#certificatereuse#C2infrastructure#detectionevasionIOCf4 · i25 · d0 · u0MITRE20RegionsCNIndustriesWholesale
C&CMembersAug 18, 2026, 14:28 (UTC+9)Three VPN-Branded Signing Identities Share One C2 Certificate
A revoked EV certificate from a company called WEILAI NETWORK TECHNOLOGY CO., LIMITED is still riding inside binaries that call themselves WireVPN. A separate, still-valid DigiCert chain issued to INNOVATIVE CONNECTING PTE. LIMITED backs a VPNMaster installer that sandboxes clean despite carrying a trojan label. And a validly signed Bright Data Ltd proxy-SDK component — the kind of software that legitimately resells residential IP addresses — comes back from a sandbox pass as a…
#WireVPN#VPNMaster#BrightData#PBotstealer#codesigningabuse#C2infrastructure#BytedanceASN#PUAmalwareActorsAPT15 · ROYALAPTIOCf12 · i8 · d4 · u0MITRE14IndustriesFood & Beverages
C&CMembersAug 17, 2026, 22:47 (UTC+9)Shared TLS Certificate Serial Links Three Unrelated Chinese ISPs
Three IP addresses sitting on three separate Chinese internet providers — China TieTong Telecommunications (AS24138), China Mobile (AS56046), and a small Jinhua, Zhejiang Province carrier operating out of AS136190 — all terminate inbound TLS connections behind a certificate issued to a domain that appears nowhere else in this indicator set: a wildcard for *.certfallback.com.
#Kimsuky#Cactusransomware#Guloader#China-basedadware#code-signingabuse#certificatetransparency#PUAdistribution#T1553.002ActorsCactus · Cactus Ransomware GroupIOCf8 · i3 · d1 · u3MITRE10
C&CMembersAug 17, 2026, 14:31 (UTC+9)Seven Alibaba IPs in Four Countries Share One TLS Certificate
Seven IP addresses split across the United States, Singapore, the Philippines and Hong Kong now answer HTTPS probes with the identical TLS certificate — a wildcard for *.certfallback.com, serial 6696262f452fcf46b79266a8, issued by GlobalSign GCC R46 OV TLS CA 2025 and valid from July 30, 2026 through February 14, 2027. That is the strongest new signal in a fresh sweep of an already-tracked proxyware-and-VPN-trojan campaign, one that in this pass added 27 domains and 12 IP addresses to the…
#proxyware#WireVPNtrojan#AlibabaCloudinfrastructure#Let'sEncryptabuse#TLScertificatereuse#BrightDataSDKabuse#C2infrastructure#PBotstealerActorsCactus · Cactus Ransomware GroupIOCf87 · i18 · d55 · u17MITRE21
C&CMembersAug 16, 2026, 22:50 (UTC+9)A Bright Data Certificate Keeps Signing Off on Worse and Worse Verdicts
A commercial proxy-network SDK's own code-signing certificate is what is holding together five different builds of a Windows binary called net_updater.exe — and the security industry's read on those builds has drifted, release over release, from potentially-unwanted software toward hacktool and adware categorization while an internal sandbox verdict flags the payload outright as a credential-stealing tool.
#BrightData#DigiCertcode-signingabuse#WireVPN#WEILAINETWORKTECHNOLOGY#revokedEVcertificate#PBotstealer#AlibabaCloudAS24429#residentialproxynetworkActorsCactus · Cactus Ransomware GroupIOCf44 · i20 · d45 · u8MITRE9
C&CMembersAug 15, 2026, 07:41 (UTC+9)Cheat-Tool Loader Feeds a Stolen-Credential Log Shop via Dual-ASN C2
A command-and-control backend built around the domain diamotrix.world is running the same check-in panel — the path /diamo/post.php — across two IP addresses sitting on entirely unrelated hosting providers, one in France and one in Germany. Feeding that backend is a PEiD-packed .NET loader distributed under the branding "B3RAP Leecher v2.exe," a tool marketed into gaming and combo-list communities rather than built for a targeted intrusion.
#diamotrix.world#B3RAPLeecher#KidnapperCloud#credentialharvesting#stealerlogs#C2infrastructure#MSILloader#cryptocurrencywallettheftIOCf47 · i2 · d1 · u7MITRE61RegionsUS
C&CMembersAug 15, 2026, 06:52 (UTC+9)Old Phorpiex Botnet Still Evades via Bare-IP Hosting, P2P C2
Six sequentially-numbered URLs — /twizt/1 through /twizt/6 — sit directly on a bare IP address, 185.215.113.84, with nothing resembling a domain name anywhere in front of them. That is unusual only in how rarely operators still do it: a Windows executable flagged by 60 of 76 engines as trojan.phorpiex/kadrbot was pulled straight from that dotted-quad host, tripping two purpose-built intrusion-detection signatures — "ET INFO Executable Download from dotted-quad Host" and "ET HUNTING SUSPICIOUS…
#Phorpiex#Kadrbot#Trikbotnet#bare-IPhosting#peer-to-peerC2#sandboxevasion#Indiagovernmentsector#commoditymalwareIOCf4 · i6 · d0 · u7MITRE31RegionsINIndustriesGovernment
C&CMembersAug 14, 2026, 22:29 (UTC+9)Sandbox-Aware Data Collector Beacons Through Rented VPN Relay Network
A 2.6-kilobyte JavaScript file quietly filed as executors/200.js — self-identified in threat classification as a "datacollector" (eb9e1d58c0…) — has been observed deliberately stalling before it runs, a behaviour flagged in its own analysis tags as staying dormant "instead of acting immediately." Once it does wake up, it beacons out to a rotating pool of IP addresses that reads less like a fixed command post and more like a rental fleet: ten of fourteen IPs tied to this activity carry an…
#datacollectormalware#sandboxevasion#VPNinfrastructure#C2beaconing#M247Europe#HostUniversalPtyLtd#JavaScriptmalware#infrastructurediversificationIOCf1 · i14 · d0 · u24MITRE11IndustriesTechnology
C&CMembersAug 13, 2026, 06:28 (UTC+9)Seven Malware Family Labels Turn Out to Be One StealC Codebase
Eleven files sitting behind a single command-and-control cluster were flagged by vendor engines as seven different malware families — StealC v2, TinyNuke, PowerLoader, Carberp, Vidar, RedLine and a Telegram-adjacent stealer tracked as MaskGramStealer. Six independent YARA rulesets and a run of IDS signatures tell a different story: several of these "families" are the same codebase and the same command-and-control protocol, wrapped in different crypto-themed lure names and shipped through…
#StealC#TinyNuke#RedLine#Vidar#MaskGramStealer#command-and-controlinfrastructure#cryptoluremalware#AS214351IOCf11 · i4 · d1 · u11MITRE45RegionsPK · USIndustriesTechnology · Telecommunications
C&CMembersAug 11, 2026, 14:48 (UTC+9)Bright Data-Signed EarnApp Loader Unchanged as 66 New Domains Surround It
The malicious file cluster that CTX Team first catalogued around a Bright Data Ltd-signed EarnApp installer has not moved: the same four binaries, the same DigiCert Trusted G4 Code Signing chain, the same detection spread running from 9 of 75 engines to 24 of 76. What has moved, sharply, is everything sitting around it. This snapshot adds 66 new domains and 19 new IPs against just 9 new file hashes — an order of magnitude more growth in registration and certificate infrastructure than in…
#EarnApp#BrightData#PBotstealer#codesigningabuse#domainregistrationfraud#Let'sEncryptcertificates#residentialproxymalware#APT28attributionActorsAPT28 · StrontiumIOCf78 · i24 · d91 · u11MITRE2IndustriesCommercial Services
C&CMembersAug 11, 2026, 06:38 (UTC+9)One DigiCert Chain, Three Chengdu Shells, 12 Signed Adware Installers
A rotating cast of Chengdu-registered shell companies has spent the past eighteen months feeding disposable code-signing identities into a single DigiCert trust chain, and the resulting installers are still walking past static AV and sandbox alike. Twelve Windows binaries examined here — installer stubs for C-drive cleaners, ad blockers, and "system optimizer" tools bundled under LuDaShi/SuperApp-style directory trees — all chain up through the same DigiCert Trusted G4 Code Signing RSA4096…
#code-signingabuse#DigiCertcertificate#Chineseadware#LudashiPUA#shellcompanysigners#sandboxevasion#APT29misattribution#ChinaTelecomJiangsuinfrastructureActorsAPT29 · MinidionisIOCf23 · i2 · d0 · u0MITRE26IndustriesWholesale
C&CMembersAug 10, 2026, 22:37 (UTC+9)Lazarus Label Rides on Thin Evidence: Old Domains, Shared Certs
A cluster of internet infrastructure carrying a Lazarus Group label arrived this month with almost nothing behind it: 29 file hashes with no signer, no size, no threat classification attached to any of them, and fifteen network indicators that sit at 0 or 1 detection out of 91 security engines, with zero community votes either way.
#LazarusGroup#mimail#certificatereissuance#CDNfronting#Incapsula#Namecheapdomains#threatattribution#commandandcontrolinfrastructureActorsLazarus Group · Hastati GroupIOCf29 · i7 · d8 · u0RegionsDE
C&CMembersAug 9, 2026, 10:54 (UTC+9)Chinese Adware Ring Reuses Certs to Spoof UnionPay and Huawei
Every piece of command infrastructure in this record — all seven IP addresses tied to the cluster — sits on a single Chinese carrier backbone, AS4837, CHINA UNICOM China169 Backbone. That alone would be a footnote for China-facing infrastructure. What makes it a story is what those IPs present to anyone who connects to them: two separate, duplicated TLS certificates, each spoofing a different trusted brand.
#code-signingabuse#TLScertificatespoofing#UnionPayimpersonation#HuaweiAppGalleryspoofing#ChinaUnicomAS4837#ludashiadware#anti-analysistechniques#PUAdistributionIOCf28 · i7 · d0 · u0MITRE14
C&CMembersAug 8, 2026, 20:44 (UTC+9)Valid Bright Data Signature Found on EarnApp Installers Flagged as PBot Stealer
Four Windows installers branded as EarnApp — the passive-income tool that pays users to resell idle bandwidth through Bright Data's proxy network — carry a fully valid Bright Data Ltd code-signing chain from DigiCert, and two of them are independently flagged by a sandbox as the "PBot" stealer family. That combination is the story here, not because a certificate was forged or revoked, but because it wasn't.
#EarnApp#BrightData#PBotstealer#code-signingabuse#DigiCert#supply-chaintrustabuse#proxyware#bandwidth-sharingmalwareIOCf69 · i22 · d98 · u9MITRE4IndustriesCommercial Services