C&CMembersJun 8, 2026, 15:26 (UTC+9)EV Certificate Issued to ORYON TECH LIMITED Signs Four Malicious Payloads in Single Batch
At 8:36 on the morning of 23 April 2026, an operator pressed the metaphorical button on a code-signing ceremony that bound four distinct malicious payloads to a single Extended Validation certificate — a credential class that Sectigo's issuance process requires to be anchored to a verified legal entity. The entity named on that certificate is ORYON TECH LIMITED.
#ORYONTECHLIMITED#Microleaves#Jatif#Legion#EVcertificateabuse#adware#Argentina#IndiaIOCf21 · i1 · d5 · u6MITRE13RegionsAR · IN
C&CMembersJun 8, 2026, 07:30 (UTC+9)Ludashi Campaign Adds Second Code-Signing Cert to Survive Revocation
##A Second Certificate, A Second Company: How the Ludashi Campaign Hardened Its Signing Infrastructure Since CTX Team's earlier coverage of the Ludashi adware and trojan campaign, twelve new file indicators, seven new IP addresses, and a new payload-delivery URL have surfaced — but the most operationally significant development is not the volume expansion.
#Ludashi#FIN6#code-signingabuse#adware#trojan#ChinaMobileAS9808#CDNfronting#DigiCertActorsFIN6 · Skeleton SpiderIOCf42 · i7 · d1 · u2MITRE13
C&CMembersJun 8, 2026, 07:18 (UTC+9)WoodyRAT Stealer Harvests Complete Exodus Wallet Secrets Across AS214351
Thirty-five new file indicators have joined the WoodyRAT-tagged campaign CTX Team first documented in earlier coverage, and almost none of them are malware. They are the stolen goods themselves — wallet seeds, two-factor secrets, session tokens, FTP credential stores, and instant-messenger account files pulled from victim machines and packaged into structured log bundles before being uploaded to a PHP panel sitting on a German IP address inside a single autonomous system registered less than…
#WoodyRAT#infostealer#Exoduswallet#Telegramsessiontheft#AS214351#cryptocurrencytheft#AlgeriaEthiopiaIndia#credentialharvestingIOCf52 · i3 · d0 · u5MITRE57RegionsDZ · ET · IN
C&CMembersJun 7, 2026, 20:10 (UTC+9)18 C2 Nodes Hide Behind Alibaba, Baidu, and 2345.com TLS Certs
Eighteen IP addresses flagged as command-and-control servers share an architectural feature that sets this campaign apart from conventional attacker-controlled hosting: every node in the set presents a TLS certificate belonging to a major Chinese internet platform — Alibaba CDN, Baidu, 2345.com, or Baidu DNS — making outbound C2 traffic structurally indistinguishable from routine HTTPS connections to some of China's highest-volume services.
#C2infrastructure#TLScertificateabuse#ChineseCDNblending#Chromeextensionmalware#sandboxevasion#ChinaUnicomAS4837#sslTrusCA#networkdetectionevasionIOCf50 · i18 · d0 · u0MITRE29
C&CMembersJun 7, 2026, 19:58 (UTC+9)Signed Adware Toolkit Targets Telecom With Two Live DigiCert Certs
Seventeen Windows executables and DLLs — spanning crash reporters, plugin managers, system tray utilities, and at least one component that a sandbox flagged as a remote-access trojan — are circulating under currently valid DigiCert Trusted G4 code-signing certificates issued to two Chinese corporate entities, with both certificates remaining valid until 2027.
#Ludashi#PubNubRAT#code-signingabuse#adware#sandboxevasion#telecommunications#DLLsideloading#ChinaActorsFIN6 · Skeleton SpiderIOCf40 · i5 · d12 · u33MITRE20IndustriesTelecommunications
C&CMembersJun 7, 2026, 19:39 (UTC+9)Gaming-Cheat Lure Hides Kernel-Level LummaStealer Campaign
A trojanized HWID-spoofer toolkit — distributed under gaming-cheat branding from at least three operator-controlled download endpoints — is delivering LummaStealer alongside a purpose-built kernel evasion stack that combines an expired EV-signed vulnerable driver with a test-certificate-signed spoofer component. The campaign's most recently observed artifact, a browser-store harvest file first seen on 2026-06-06, confirms active credential collection was underway within hours of CTX Team's…
#LummaStealer#BYOVD#WinDivert#kernelevasion#gamingcommunitytargeting#credentialtheft#HWIDspoofer#APT28unconfirmedActorsAPT28 · StrontiumIOCf17 · i5 · d3 · u6MITRE24
C&CMembersJun 7, 2026, 07:53 (UTC+9)CDN-Masquerade TLS Cluster and First C2 Domain Expand PubNubRAT Campaign
Thirteen IP addresses spanning six Chinese autonomous systems — China Unicom, China Telecom, China Mobile, and Jinhua Weian InfoTech among them — have been found presenting an identical Sectigo DV wildcard certificate for *.bytecdn.cn (serial 152bfd07c372d944c3ac6feff2e606bd), forming a geographically distributed reverse-proxy layer that cloaks command-and-control traffic behind the TLS identity of one of China's largest consumer internet CDN brands.
#PubNubRAT#TLSmasquerade#C2infrastructure#codesigningabuse#China#PUA#reverseproxy#CDNimpersonationActorsFIN6 · Skeleton SpiderIOCf73 · i77 · d1 · u2MITRE10
C&CMembersJun 7, 2026, 03:54 (UTC+9)APT27 Toolkit Ties Six Malware Families to One C2 Cluster
Nine Windows executables submitted to VirusTotal across a five-day window in late May and early June 2026 do not look, at first glance, like a coordinated campaign. The threat labels scatter across the taxonomy — a banker trojan here, a clipboard hijacker there, an EDR-bypass pair, a StealC loader, an Amadey dropper. The file sizes range from 42 KB to 868 KB. No shared code-signing certificate ties them together.
#APT27#StealCv2#Amadey#ClipBanker#reflectiveloading#EDRbypass#Algeria#bulletproofhostingActorsAPT27 · TEMP.HippoIOCf64 · i3 · d0 · u7RegionsDZ
C&CMembersJun 7, 2026, 03:39 (UTC+9)TA505 Hides Malware Behind 13-Year-Old Revoked Valve Certificate
A SilverFox dropper circulating since early June 2026 carries a Valve Corporation code-signing certificate that expired in November 2012 and has been explicitly revoked — yet its PE timestamp reads 2025-08-18, a 13-year anachronism that is the clearest single indicator of deliberate stolen-cert abuse in this campaign. That certificate is only the first layer of a defense-evasion stack that also includes a Bring Your Own Vulnerable Driver (BYOVD) technique using a legitimately signed WinDivert…
#TA505#LummaStealer#SalatStealer#Amadey#BYOVD#certificateabuse#gamingcommunitytargeting#TurkeyActorsTA505 · Hive0065IOCf16 · i5 · d2 · u7MITRE27
C&CMembersJun 6, 2026, 23:59 (UTC+9)One DigiCert Certificate, 17 Malicious Payloads, Three-Year Signing Window
In September 2024, someone registered a code-signing certificate with DigiCert under the name of a Beijing technology company — 北京创想界科技有限公司 — and within six weeks began using it to sign malicious software. By the time CTX Team catalogued the full file cohort, that single certificate, serial number 06 FE 57 2B A6 2E 8E C3 18 03 0F DC 9B AC A2 81, had been applied to 17 distinct PE32 executables and DLLs spanning two trojanized utility brands, a modular plugin architecture, and at least one…
#PubNubRAT#Ludashi#PolarWind#code-signingabuse#Chinesethreatactor#CDNinfrastructure#sandboxevasion#adwaredual-useActorsAPT28 · StrontiumIOCf42 · i65 · d0 · u0MITRE26
C&CMembersJun 6, 2026, 15:47 (UTC+9)Salty Spider Adds Second CDN Channel to Trojanized 2345PCSafe Delivery
Since CTX Team's earlier coverage of this campaign, the delivery infrastructure backing the trojanized 2345PCSafe (2345安全卫士) security suite has grown in a specific and operationally significant direction: a second CDN-fronted update endpoint, dl-up.2345cdn.com, is now confirmed active alongside the previously documented download.2345cdn.com, and 23 additional IP addresses have been mapped to the anycast pools behind both domains.
#SaltySpider#2345PCSafe#ad2345#chinad#supplychaincompromise#CDNabuse#codesigningabuse#mainlandChinaActorsSalty Spider · KuKuIOCf59 · i25 · d2 · u2MITRE2
C&CMembersJun 6, 2026, 11:58 (UTC+9)Three Certs, One Chain: Signed Adware Campaign Evades Revocation for 8 Months
Seventeen signed Windows executables, three DigiCert code-signing certificates, three distinct Chinese corporate identities, and an eight-month continuous production window: what CTX Team has catalogued in this campaign is not a single malicious installer but an industrialised signing infrastructure engineered to survive the most common defensive response to signed malware — certificate revocation.
#TA551#Ludashi#Chinad#code-signingabuse#certificaterotation#sandboxevasion#China-nexus#adware-trojanActorsTA551 · ShathakIOCf35 · i18 · d3 · u0MITRE3
C&CMembersJun 6, 2026, 11:40 (UTC+9)APT28 Hides PBot Stealer Inside Validly Signed Bright Data SDK Binary
A 12-megabyte Windows executable carrying a fully valid DigiCert code-signing certificate for "Bright Data Ltd" — a commercially distributed proxy and VPN software vendor — is circulating as the stealth layer of an espionage toolkit that CTX Team has attributed to APT28, the Russian state-aligned threat group also tracked under aliases including Fancy Bear, Forest Blizzard, and Sofacy.
#APT28#PBotstealer#BrightDataSDKabuse#code-signingchainexploitation#KMSactivationlure#C2certificaterotation#Dotfuscatorpacking#CloudflareproxyingActorsAPT28 · StrontiumIOCf4 · i2 · d7 · u1MITRE11
C&CMembersJun 6, 2026, 07:32 (UTC+9)Five-Family Infostealer Campaign Bypasses Chrome 127 Encryption via Single Rogue AS
A multi-stage infostealer and clipboard-hijacking campaign deploying at least five distinct malware families — Amadey, StealC v2, two statically linked ClipBanker variants, and a purpose-built custom dropper — has been routing all of its command-and-control traffic exclusively through AS214351, a single autonomous system operated by Femo It Solutions Limited that was created in October 2024 and spans address space registered under two separate regional internet registries.
#Amadey#StealCv2#ClipBanker#AS214351#Chromiumapp-boundencryptionbypass#clipboardhijacking#crimewareinfrastructure#BrazilIOCf43 · i3 · d0 · u7RegionsBR
C&CMembersJun 6, 2026, 03:38 (UTC+9)Three Chinese Firms Rotate DigiCert Certs to Keep Adware Trusted
Twenty Windows executables and DLLs — every single one carrying a valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 signature — are circulating under the guise of security and system-optimisation software, with the signing authority rotating across three distinct Chinese corporate entities to sustain a trusted posture as individual certificates accumulate antivirus detections.
#Ludashi#Polarwind#DigiCertcertificateabuse#code-signingrotation#adware-trojan#China#CDNinfrastructureevasion#SaltySpiderActorsTA551 · ShathakIOCf58 · i72 · d3 · u3MITRE8
C&CMembersJun 6, 2026, 00:07 (UTC+9)One DigiCert Certificate Binds 18 Malicious Ludashi Components Through 2027
Eighteen Windows PE files — a mix of executables and DLLs spanning a full PC utility lifecycle, from disk defragmentation to a lockscreen manager to an uninstaller — are circulating under the Ludashi (鲁大师) software brand, every one of them bearing an identical, currently-valid DigiCert Trusted G4 code-signing certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co. Ltd.).
#ChengduQiluTechnology#Ludashi#Chinad#adware#code-signingabuse#fast-fluxDNS#TLSimpersonation#ChinaIOCf66 · i5 · d2 · u4MITRE19
C&CMembersJun 5, 2026, 08:24 (UTC+9)Signed-Adware Campaign Adds PubNubRAT and New C2 Backend
Since CTX Team's earlier coverage of this campaign's UnionPay-fingerprinted TLS infrastructure, the operation has expanded in two structurally significant directions: a wholly new, function-partitioned command-and-control backend has been provisioned under the domain tjbxldkj.cn, and eight fresh IP addresses bound by a shared Sectigo wildcard certificate have joined the delivery layer — all absent from the prior reporting.
#PubNubRAT#code-signingabuse#China-nexusthreatactor#cloudC2evasion#PCoptimizermalware#DigiCertcertificatemisuse#CDNdeliveryinfrastructure#sandboxevasionIOCf31 · i8 · d4 · u3MITRE23
C&CMembersJun 5, 2026, 08:07 (UTC+9)Stealc v2 Chromium Bypass Moves to Active Campaign in Vietnam
Three Windows executables circulating in a Vietnam-region campaign have been confirmed by sandbox analysis and six independent YARA rules as carrying Stealc v2's built-in bypass for Chromium app-bound encryption — a credential-protection mechanism Google introduced in 2024 specifically to block the kind of browser-password extraction that infostealer markets had relied on for years.
#Stealcv2#Amadey#clipboardhijacker#Chromiumapp-boundencryptionbypass#Vietnam#AS214351#credentialtheft#cryptocurrencytheftIOCf20 · i3 · d9 · u4MITRE31RegionsVN
C&CMembersJun 4, 2026, 23:51 (UTC+9)Phorpiex Botnet Runs Six-Path C2 Panel With Tor Fallback to Target Mexico
A single IP address geolocated to the Seychelles is currently serving six sequentially numbered HTTPendpoints — /cc11, /cc22, /cc33, /cc44, /cc55, and /cc66 — alongside a Tor hidden-service fallback, forming the operational backbone of an active Phorpiex botnet campaign targeting Mexico. CTX Team first observed this infrastructure on 4 June 2026.
#Phorpiex#botnet#C2infrastructure#sandboxevasion#Torhiddenservice#Mexico#ransomware#time-basedevasionIOCf3 · i3 · d1 · u7MITRE36RegionsMX
C&CMembersJun 4, 2026, 23:40 (UTC+9)Ludashi Campaign Staged Eight C2 Subdomains Four Months Before First Payload
Since CTX Team's earlier coverage established the signed-binary tradecraft at the core of this operation, the picture of how those payloads reach victims has come into focus. The new signal is entirely network-side: eight xhyktech.com subdomains provisioned in a single registration batch on 2025-03-10, three of them now unified under a wildcard TLS certificate issued by the Chinese CA iTrust, Inc.
#Ludashi#ZXStoreX#xhyktech.com#adware#CDNfronting#codesigningabuse#Chinesethreatinfrastructure#pluginloaderIOCf13 · i3 · d8 · u9MITRE43
C&CMembersJun 4, 2026, 11:37 (UTC+9)Shell Companies, Signed Malware, and a RAT Hidden in a PC Cleaner
Seventeen Windows binaries circulating across Chinese consumer software ecosystems carry valid DigiCert Trusted G4 Code Signing certificates — but the two Chengdu-registered entities that obtained those certificates appear to exist solely to launder signing trust onto malicious code. The scheme is not a one-off: CTX Team's analysis documents a deliberate rotation cycle spanning more than two years, with one entity procuring a replacement certificate within the same month its predecessor expired…
#PubNubRAT#code-signingabuse#Ludashiecosystem#shellcompanyinfrastructure#ChinaUnicombackbone#certificaterotation#supply-chaindelivery#sandboxevasionIOCf39 · i16 · d0 · u0MITRE17
C&CMembersJun 4, 2026, 07:38 (UTC+9)Sality Botnet Still Active After 15 Years, Adds Zero-Detection Payload
Fourteen distinct HTTP beacon paths. Two C2 domains. A core sample that has been resubmitted to threat intelligence platforms continuously from July 2010 through October 2025. And, sitting at the edge of this campaign, a file submitted just days before this analysis — typed as JSON, carrying zero detections across 76 engines, with an alternate name pointing to a randomised executable path buried deep inside Program Files. The Sality polymorphic file-infector is not a relic.
#SaltySpider#Sality#Expiro#Tofsee#polymorphicfile-infector#USBautorun#Cameroon#C2infrastructureActorsSalty Spider · KuKuIOCf31 · i1 · d5 · u17RegionsCM
C&CMembersJun 3, 2026, 23:52 (UTC+9)Stealc v2, ClipBanker, AgentB Hit Crypto Wallets via Single Rogue ASN
A financially motivated campaign active through May and June 2026 has deployed three functionally distinct malware families — Stealc v2, a ClipBanker, and an AgentB-family trojan — against the same command-and-control infrastructure, producing confirmed victim artefacts that include four encrypted Exodus cryptocurrency wallet files and a FileZilla FTP credential store.
#Stealcv2#ClipBanker#AgentB#cryptocurrencytheft#AS214351#importtableobfuscation#Exoduswallet#infostealerIOCf30 · i2 · d0 · u5MITRE43RegionsRS
C&CMembersJun 3, 2026, 13:58 (UTC+9)1-of-76 Dropper Anchors Two-Year Microsoft Path Masquerade Campaign
A freshly compiled Windows executable detected by exactly one of 76 antivirus engines sits at the entry point of a multi-layered implant campaign that has been quietly refreshing its toolset for the better part of two years. The file calls itself SecurityHealthServiceSyncUpdate.exe, drops under C:\Program Files\Microsoft\Servicing\, and carries a PE compile timestamp of 2026-05-13 — one day before it first appeared on VirusTotal.
#SpringDragon#LotusBlossom#proxyware#trojanproxy#Microsoftpathmasquerade#Cloudflarefronting#APTespionage#WindowsimplantActorsSpring Dragon · Lotus BlossomIOCf6 · i7 · d3 · u0MITRE9
C&CMembersJun 3, 2026, 09:00 (UTC+9)TA505 Campaign Climbs Certificate Trust Ladder to Zero-Detection EV Binary
A single campaign distributing trojanized KMS activators and download-manager reset tools has assembled one of the more deliberately layered code-signing abuse chains CTX Team has documented in recent months: an expired Sectigo leaf certificate that still evades roughly 38 antivirus engines, a currently valid DigiCert chain carrying a MediaGet PUA, and — at the top of the trust ladder — a valid Extended Validation certificate issued to DeepL SE under GlobalSign's GCC R45 hierarchy, producing a…
#TA505#code-signingabuse#EVcertificate#KMSactivatorlure#ramnit#DLLsideloading#fast-fluxC2#credentialharvestingActorsTA505 · Hive0065IOCf10 · i3 · d2 · u0MITRE29
C&CMembersJun 3, 2026, 08:25 (UTC+9)Expired 2022 EV Timestamp Lets LockBit's IP Scanner Slip Past 74 of 76 AV Engines
A Varist-packed Windows executable weighing just over 20 megabytes is circulating via a spearphishing link at adbuho.shop/iqoja, presenting itself as the legitimate Famatech Corp. Advanced IP Scanner installer — and walking past 74 of 76 antivirus engines in the process. The secret to that near-total evasion is not a novel obfuscation technique or a freshly minted fraudulent certificate.
#LockBitGang#AdvancedIPScanner#code-signingabuse#living-off-the-land#Authenticodetimestamp#spearphishing#C2infrastructure#MediaFireCDNabuseActorsLockbit GangIOCf2 · i5 · d4 · u2MITRE4
C&CMembersJun 3, 2026, 04:26 (UTC+9)Fake Speed-Checker Masks a Decade-Long PUP Distribution Platform
Sixteen HTTPS requests. Two path templates. One hardcoded affiliate token. The architecture behind a shlayer-family PUP operation targeting energy-sector endpoints turns out to be less a piece of malware and more a managed distribution platform — one whose C2 infrastructure has been actively maintained into 2026 despite payload files that first appeared on VirusTotal in the summer of 2015.
#shlayer#PUPdistribution#C2infrastructure#affiliatetoken#self-signedcertificate#energysector#HTTPSmasquerade#update.buffernavpose.comIOCf2 · i0 · d1 · u16MITRE15IndustriesEnergy
C&CMembersJun 2, 2026, 08:31 (UTC+9)Prometei Botnet Runs Three Years on SSH Exploits, One C2 Still Live
A 303-kilobyte Windows executable has been circulating since at least February 2023, quietly fetched by hosts compromised through internet-facing SSH and Telnet services, dropped into a Dell-branded subdirectory under a deliberately misspelled filename, and phoning home to a two-tier command-and-control architecture that spans a now-sinkholed domain and an active fast-flux node still live as of June 2026.
#Prometei#OilRig#Cactusransomware#SSHexploitation#healthcare#telecommunications#botnet#command-and-controlinfrastructureActorsOilRig · APT34IOCf2 · i1 · d2 · u2MITRE9IndustriesHealthcare · Telecommunications
C&CMembersJun 2, 2026, 08:17 (UTC+9)13-Node C2 Pool Borrows UnionPay Wildcard TLS to Mask Ludashi Adware
Thirteen China-geolocated IP addresses, distributed across five distinct autonomous systems, are presenting a wildcard TLS certificate belonging to UnionPay International Co., Ltd. as their HTTPS identity — a trust-borrowing technique that gives campaign traffic the appearance of legitimate Chinese financial-sector communications.
#Ludashiecosystem#UnionPaycertificateabuse#code-signingevasion#C2infrastructure#ChinaISP#adware#TLStrustabuse#DigiCertActorsFIN6 · Skeleton SpiderIOCf58 · i14 · d1 · u0MITRE3IndustriesTelecommunications
C&CMembersJun 2, 2026, 01:59 (UTC+9)One Signing Session Armed a Full Adware Suite With a Valid DigiCert Cert
On the morning of August 30, 2023, someone with access to Shanghai 2345 Mobile Technology Co., Ltd.'s code-signing infrastructure sat down and signed nine Windows components in rapid succession — SafeUpdate.dll at 7:36 AM, Optimize.dll at 7:34 AM, Exam.dll at 7:33 AM, AvScan.dll at 7:32 AM, and five more within the same narrow window.
#SaltySpider#2345PCSafe#adware#code-signingabuse#AlibabaKunlunCDN#ad2345#Amadey#ChinaActorsSalty Spider · KuKuIOCf40 · i13 · d1 · u2MITRE2
C&CMembersJun 1, 2026, 17:38 (UTC+9)One DigiCert Cert, 22 New Payloads: Inside a Chinese Adware Signing Pipeline
Since CTX Team's earlier coverage of this operation, twenty-two additional signed Windows executables and five new command-and-control IP addresses have surfaced under the same Chengdu-registered signing identity — all bearing a DigiCert code-signing certificate that remains valid until May 2027 and has not been revoked. The expansion confirms that the operator behind 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co.
#FIN6#adware#code-signingabuse#LuDaShisideloading#China#DigiCertcertificate#tjbxldkj.cn#consumerendpointActorsFIN6 · Skeleton SpiderIOCf41 · i13 · d7 · u9MITRE9
C&CMembersJun 1, 2026, 07:00 (UTC+9)Salty Spider Pivots to Valid WPS Certificate for Near-Invisible Telecom Implant
Six Windows executables circulating as VPN and proxy clients are carrying code-signing certificates from two Singapore-registered entities — INNOVATIVE CONNECTING PTE. LIMITED and WEILAI NETWORK TECHNOLOGY CO., LIMITED — whose DigiCert and GlobalSign EV credentials expired in April 2026 yet continue to present intact Authenticode chains that most endpoint controls will not challenge.
#SaltySpider#code-signingabuse#EVcertificate#VPNMaster#KingsoftWPSOffice#telecommunications#Asia-Pacific#trojanisedinstallerActorsSalty Spider · KuKuIOCf6 · i14 · d39 · u4MITRE13IndustriesTelecommunications
C&CMembersJun 1, 2026, 06:27 (UTC+9)Ludashi C2 Expands: Two .cn Clusters, Shared IPs, and a New Browser Injector
Nine new domains and 13 IP addresses have been added to the Ludashi campaign's observable footprint since CTX Team's earlier coverage, and the infrastructure picture they complete is more deliberate than the raw count suggests. Two parallel command-and-control domain families — whnuowo.cn and tjbxldkj.cn — are now fully mapped, their subdomains provisioned in coordinated batches under iTrust DV wildcard certificates, their config endpoints resolving to a single shared IP that stitches the two…
#Ludashi#FIN6#TA428#MasterBHO#PubNubRAT#browserhelperobject#commandandcontrol#ChinaActorsFIN6 · Skeleton SpiderIOCf31 · i13 · d9 · u6MITRE9
C&CMembersJun 1, 2026, 00:45 (UTC+9)Four Corporate Fronts, One Build Pipeline: 18-Month DigiCert Signing Spree
Fifteen signed Windows executables. Four registered Chinese companies. One DigiCert certificate authority chain threading through all of them. The campaign CTX Team has been tracking across an 18-month window does not rely on a single forged credential or a stolen certificate — it relies on something more durable: a systematic program of acquiring legitimate DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 certificates under distinct corporate identities, then rotating those identities…
#DigiCertcertificateabuse#Authenticodesigningrotation#PEoverlaytechnique#sandboxevasion#Ludashi#PubNubRAT#Chinesefrontcompanies#consumersoftwarebundlingIOCf86 · i8 · d1 · u1MITRE25
C&CMembersMay 31, 2026, 18:00 (UTC+9)Ludashi Adware Operator Rotates to Third DigiCert Certificate Across Three Chinese Entities
Since CTX Team's earlier coverage of the Ludashi/LuDaShi adware ecosystem, 26 additional signed PE files and 97 IP addresses have surfaced, and the most operationally significant development is not the volume — it is what the new files reveal about how the operator manages its code-signing infrastructure. A third DigiCert G4 code-signing certificate, issued to a third distinct Chinese legal entity, has now appeared in the campaign, completing a picture of deliberate, institutionalized identity…
#Ludashi#code-signingabuse#certificaterotation#adware#Chinesethreatactor#C2infrastructure#DigiCert#defenseevasionActorsFIN6 · Skeleton SpiderIOCf47 · i97 · d0 · u0MITRE6
C&CMembersMay 31, 2026, 09:10 (UTC+9)Signed Bright Data SDK Delivers PBot Stealer via Three-Layer Evasion Stack
A 9.27-megabyte Windows executable, validly signed under a live DigiCert code-signing chain issued to Bright Data Ltd, is circulating as a trojanised update component placed directly inside Bright VPN and DriverHub installation directories — a delivery mechanism that exploits the grey-area status of commercial proxy-network software to suppress detection across the majority of the antivirus industry.
#PBot#BrightDataSDK#code-signingabuse#Dotfuscatorobfuscation#CDNcertificatemasquerading#commercialservicessector#China-geolocatedinfrastructure#supplychaindeliveryIOCf41 · i17 · d2 · u0IndustriesCommercial Services
C&CMembersMay 31, 2026, 08:55 (UTC+9)Dual DigiCert Certs Keep Ludashi Adware Invisible for 15 Months
Sixteen Windows executables carrying valid, unrevoked DigiCert code-signing certificates issued to two distinct Chinese companies have been circulating as trojanized PC-optimization installers across a fifteen-month window — a sustained signed-binary abuse campaign that returns a clean verdict from every sandbox that examines it, even as detection ratios on the same files reach as high as 38 of 77 engines on VirusTotal.
#Ludashi#code-signingabuse#Authenticodeevasion#adware#ChinesePUA#whnuowo.cn#DigiCertcertificateabuse#CDN-frontedC2ActorsTA551 · ShathakIOCf32 · i23 · d5 · u2MITRE6
C&CMembersMay 31, 2026, 08:41 (UTC+9)Upatre C2 Cluster Exploits Freshly Allocated French IP and 16-Year-Old Domain
Since CTX Team's earlier coverage of this Upatre dropper campaign targeting US media-sector organisations, the infrastructure picture has sharpened considerably. The update adds no new file samples — the dropper payload itself remains unchanged — but surfaces one new C2 IP address, two new domains, and three confirmed URL-form beacon paths that together complete a hosting architecture the prior snapshot could only partially sketch.
#Upatre#Waski#C2infrastructure#USmediasector#domainre-weaponisation#OrangeAS5511#droppercampaign#Let'sEncryptabuseIOCf3 · i1 · d2 · u3MITRE17RegionsUSIndustriesMedia
C&CMembersMay 31, 2026, 04:56 (UTC+9)Three-Layer Evasion Stack Targets Education Networks via Per-Victim Phishing URLs
Thirteen individualised phishing URLs, each carrying a distinct base64-encoded payload that fingerprints the victim's browser before deciding whether to proceed — that is the opening move of a campaign CTX Team has been tracking against the education and research sector, built on infrastructure that layers domain-generation algorithm tagging, fast-flux DNS across eight A-records at 60-second TTLs, and a CNAME redirect through a secondary unanalysed domain, all backed by freshly provisioned…
#spearphishing#fast-fluxDNS#browserfingerprinting#educationsector#C2infrastructure#domaingenerationalgorithm#redirectchain#credentialharvestingIOCf0 · i2 · d1 · u13MITRE10IndustriesEducation & Research
C&CMembersMay 30, 2026, 23:28 (UTC+9)Phorpiex Botnet Splits C2 Across Russian and AFRINIC Hosts to Resist Takedown
A single 14-kilobyte Windows executable — compact enough to fit in a single memory page — is beaconing outward to two command-and-control servers that have been deliberately placed in different corners of the internet's address space. One sits inside a subnet allocated to Prospero OOO, a St. Petersburg-registered provider operating under AS200593 through RIPE NCC, and carries a short-lived Let's Encrypt certificate for the domain "ledgersinsured.com" as its TLS cover.
#Phorpiex#botnetC2infrastructure#ProsperoOOO#AFRINIC#ransomware#Uzbekistan#TLScertificateabuse#wormpropagationIOCf1 · i2 · d0 · u8MITRE47RegionsUZ
C&CMembersMay 30, 2026, 07:04 (UTC+9)Trojanised VPN Installer Weaponises Two Legitimate Code-Signing Chains
A 14.5-megabyte NSIS self-extracting archive named WireVpn_v3.6.0.3-6872e76.exe has been circulating through a curated software-distribution channel labelled "TS Recommended Apps" — bearing a valid Extended Validation code-signing certificate from GlobalSign, issued to a Chinese-registered entity called WEILAI NETWORK TECHNOLOGY CO., LIMITED, and dropping kernel-level netfilter drivers alongside proxy and jumper binaries that collectively form an espionage-oriented command-and-control platform.
#WireVPN#PBot#WEILAINETWORKTECHNOLOGY#BrightDataSDK#code-signingabuse#netfilterkerneldriver#signedbinaryproxyexecution#credentialstealerActorsSprite Spider · Gold DupontIOCf27 · i27 · d94 · u12MITRE24
C&CMembersMay 30, 2026, 00:50 (UTC+9)Sequential C2 Panel Paths Expose Seychelles-Registered Bulletproof Hosting Behind Spain Infostealer Campaign
Three new command-and-control IP addresses have surfaced in the latest observation window of a SmokeLoader and Rhadamanthys infostealer campaign targeting victims in Spain — and the way those addresses were provisioned tells a more precise story than the malware families themselves. Two of the IPs share a single autonomous system number, AS202412, registered to Omegatech LTD, a Seychelles-incorporated entity whose RIPE NCC address block allocations were created within a single month of each…
#SmokeLoader#Rhadamanthys#bulletproofhosting#credentialtheft#Spain#cryptocurrencywallettheft#C2infrastructure#infostealerActorsAPT28 · StrontiumIOCf34 · i3 · d0 · u4MITRE49RegionsES
C&CMembersMay 29, 2026, 20:56 (UTC+9)Six-Year-Old Phorpiex Dropper Hits Kazakhstan on Fresh Romanian VPS
A 412-kilobyte Windows executable — unsigned, packed, and masquerading as a tape-toolbar utility from the year 2000 — has been actively beaconing to a freshly provisioned Romanian virtual private server since at least March 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan.
#Phorpiex#ClipBanker#USBworm#Kazakhstan#educationsector#governmentsector#clipboardhijacking#commoditybotnetIOCf8 · i1 · d0 · u10MITRE36RegionsKZIndustriesEducation & Research · Government
C&CMembersMay 29, 2026, 14:28 (UTC+9)PBot Stealer Gets 64-Bit Rebuild, Drops to 9/76 Detections
Since CTX Team's earlier coverage of this VPN-lure PBot stealer campaign, the most operationally significant development is not the expansion of the domain or IP set — though both have grown substantially — but a single freshly compiled binary that signals the operator is actively retooling the payload build pipeline rather than coasting on existing artifacts.
#ramnit#beaconIOCf9 · i28 · d51 · u6MITRE23
C&CMembersMay 28, 2026, 22:40 (UTC+9)Trojanized Security Suite Uses Valid DigiCert Cert to Blind Sandboxes
Nine PE32 components masquerading as a legitimate Chinese consumer security product are circulating with a currently-valid DigiCert code-signing certificate, a direct-syscall evasion technique confirmed by YARA, and payload delivery routed through Alibaba's KunlunCan CDN — a combination that collapses sandbox verdicts to zero while roughly half of antivirus engines still flag the files on static analysis alone. The gap between those two numbers is the operational story of this campaign.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf9 · i21 · d2 · u5MITRE22
C&CMembersMay 28, 2026, 22:28 (UTC+9)One DigiCert Cert, 14 Executables, Nine Months Undetected
Fourteen distinct Windows executables. Six different product personas. One code-signing certificate — and nine months of continuous, largely undetected operation. That is the operational picture CTX Team has assembled from a cluster of signed PE32 binaries circulating through the Ludashi PUA distribution ecosystem, all stamped with a single DigiCert certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid through 2027-05-20).
#FIN6#Group123#SaltySpider#lockergoga#salityActorsFIN6 · Skeleton SpiderIOCf23 · i25 · d4 · u1MITRE11
C&CMembersMay 28, 2026, 18:31 (UTC+9)One EV Certificate, Two Trojans, Three Fake Windows Binaries
Two trojan.jumper payloads circulating under the guise of a WireVPN client share an identical GlobalSign Extended Validation code-signing certificate — serial 03 A9 18 8A A5 10 C0 F8 34 34 26 BF, issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED — while three companion files masquerade as canonical Windows system executables, carrying valid Microsoft signatures and zero detections across 76 scanning engines.
#beacon#AutomotiveIOCf6 · i6 · d6 · u0MITRE12IndustriesAutomotive
C&CMembersMay 28, 2026, 18:11 (UTC+9)Space Pirates Add Signed .NET Stealer to Trojanized-VPN Arsenal
Since CTX Team's earlier coverage of this campaign, eight new malicious files and a complete refresh of 18 IP addresses and 26 domains have surfaced — but the most operationally significant development is not the scale of the infrastructure turnover. It is the addition of a third signed-binary abuse vector: a Dotfuscator-packed, encrypted .NET stealer classified as PBot, hidden inside a binary carrying a valid Bright Data Ltd code-signing certificate.
#SpacePirates#ramnit#beaconActorsSpace Pirates · WebwormIOCf14 · i18 · d26 · u4MITRE17
C&CMembersMay 28, 2026, 06:11 (UTC+9)Ludashi PUA Pivots to Cloud-Fronted C2 via Tencent API Gateway
Since CTX Team's earlier coverage of the Ludashi PUA campaign, the observable infrastructure has undergone a complete turnover: twelve new IP addresses, six new domains, and seven new URLs have entered the active indicator set, while every previously tracked file has rotated out. The payload layer is quiet — zero new binaries — but the network layer tells a story of deliberate, operationally sophisticated infrastructure replacement.
#TA551#icedidActorsTA551 · ShathakIOCf19 · i12 · d6 · u7MITRE12
C&CMembersMay 28, 2026, 02:13 (UTC+9)Fake Speed-Test Utility Hides Eight-Year C2 Network With *.malware.com Cert
Two subdomains. One IP address. One self-signed TLS certificate whose common name is literally *.malware.com. The infrastructure behind a shlayer-attributed potentially unwanted program (PUP) campaign targeting the energy sector is not subtle — but its longevity is. The parent domain buffernavpose.com was registered on 2018-05-12 via Dynadot Inc, has been actively maintained through at least April 2026, and carries a certificate valid until 2030-05-11.
#shlayer#EnergyIOCf2 · i0 · d2 · u10MITRE15IndustriesEnergy