C&CMembersMay 27, 2026, 21:54 (UTC+9)Six-Year-Old Batch Script Powers 2025 Telecom Espionage Campaign
A trojanised ZIP archive impersonating the legitimate Microsoft Activation Scripts open-source project is circulating across enterprise endpoints, embedding active sandbox-evasion logic inside what victims perceive as a trusted Windows activation utility — and funnelling compromised hosts toward a freshly constructed, deliberately compartmentalised command-and-control infrastructure spanning three distinct autonomous systems with no cross-node certificate or DNS linkage between them.
#TA505#Cactus#goldeneye#TelecommunicationsActorsTA505 · Hive0065IOCf2 · i2 · d1 · u17MITRE4IndustriesTelecommunications
C&CMembersMay 27, 2026, 18:11 (UTC+9)WireVPN Campaign Adds 132 Domains and a PBot Stealer Component
Fifty-five new command-and-control IPs and 132 additional domains have joined the Trojan.Jumper/WireVPN campaign's observable footprint since CTX Team's earlier coverage, transforming what was a 15-domain, 9-ASN operation into a multi-continent hosting fabric organised across five named fingerprint clusters. The expansion is not random: every cluster is bound by a shared certificate issuer, autonomous system, or registrar identity, and the core payload chain — three PE32 executables all signed…
#SpacePirates#CactusActorsSpace Pirates · WebwormIOCf4 · i55 · d132 · u19MITRE14
C&CMembersMay 27, 2026, 17:56 (UTC+9)Salty Spider Expands to Dual-Domain C2 With UnionPay TLS Fingerprint
Nine command-and-control domains, nine documented URL paths, and 31 IP addresses — none present in prior coverage — have surfaced in the latest observed activity tied to the Salty Spider campaign, exposing for the first time the full operational infrastructure behind a signed-binary adware toolkit that CTX Team has been tracking across multiple observation windows.
#SaltySpider#lummastealer#salityActorsSalty Spider · KuKuIOCf51 · i31 · d9 · u9MITRE8
C&CMembersMay 27, 2026, 13:52 (UTC+9)Trojan.Jumper Builds Five-Tier C2 Across 15 Domains and 9 ASNs
Fifteen new domains. Nine IP addresses spanning six autonomous systems across four continents. Five distinct certificate-issuer fingerprints provisioned within a 45-day window. Since CTX Team's earlier coverage of the Trojan.Jumper campaign, the operator has not merely maintained an existing footprint — they have constructed a layered, multi-tier command-and-control architecture that reveals a level of infrastructure investment inconsistent with opportunistic or low-sophistication adversaries.
#GovernmentIOCf4 · i9 · d15 · u4MITRE18IndustriesGovernment
C&CMembersMay 26, 2026, 22:40 (UTC+9)One DigiCert Cert Signed 16 Malicious Binaries Across 18 Months
Sixteen distinct Windows binaries. Eight separate product personas. One DigiCert code-signing certificate — and not a single revocation in eighteen months. That is the operational core of a sustained adware and data-harvesting campaign that CTX Team has been tracking across the Ludashi (鲁大师) software ecosystem, where malware dressed as Chinese security utilities has been circulating since at least November 2024.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf30 · i25 · d9 · u9MITRE12
C&CMembersMay 26, 2026, 21:16 (UTC+9)AS214351 Adds 'PureCrack' Relay Node and DGA Domains in C2 Expansion
Since CTX Team's earlier coverage of this financially motivated campaign — documented then as a raw-IP beaconing operation running six malware families across a single young autonomous system — ten new files, two algorithmically generated domains, and a second command-and-control IP have surfaced. The most operationally significant addition is not another payload variant but a structural change to the hosting fabric itself: 196.251.107.104, a new node within AS214351 operated by Femo IT…
#AS214351#FemoITSolutions#Stealcv2#BazarLoader#Amadey#clipboardhijacker#bulletproofhosting#DGAdomainsIOCf20 · i3 · d2 · u5MITRE18RegionsAL · BO · CA · DE
C&CMembersMay 26, 2026, 21:02 (UTC+9)Dual-Cert Trojan VPN Pipeline Targets Food and Beverage Sector
Five Windows executables are circulating as components of a legitimate-looking VPN product — each carrying a valid-chain code-signing certificate issued to one of two shell entities, "INNOVATIVE CONNECTING PTE. LIMITED" and "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — while quietly establishing proxy-chain command-and-control infrastructure anchored in a Chengdu internet data centre.
#Barium#APT15#Cactus#ramnit#FoodBeveragesActorsBarium · Wicked SpiderIOCf10 · i18 · d23 · u3MITRE7IndustriesFood & Beverages
C&CMembersMay 26, 2026, 20:44 (UTC+9)Five Shell Companies, One Adware Campaign: DigiCert Cert Rotation Exposed
Thirty-one signed Windows binaries. Five distinct Chinese legal entities. One certificate authority. The Ludashi adware ecosystem — distributed under the guise of utility software products with names like LargeFileClean, WhaleMemory, Mem Optimization Pro, DupsClean, and CipherLock — has been running a sustained code-signing rotation strategy that goes well beyond what commodity adware operators typically invest in.
#FIN6#lockergoga#icedidActorsFIN6 · Skeleton SpiderIOCf31 · i4 · d12 · u8MITRE35
C&CMembersMay 26, 2026, 17:06 (UTC+9)Four Signed Certs, Ten IPs, One UnionPay Disguise: IcedID's Dual-Layer Evasion
Seventeen Windows executables and DLLs, all validly signed by DigiCert's Trusted G4 Code Signing chain, are circulating as system-cleaning and security utilities — and every one of them beacons to a C2 backend whose ten IP addresses present a wildcard TLS certificate issued to UnionPay International Co., Ltd. The combination is not accidental.
#icedidIOCf25 · i10 · d2 · u2MITRE46
C&CMembersMay 26, 2026, 16:51 (UTC+9)APT28 Burns Fake Cert, Hides Agent Behind Legit Vendor Signature
Two Windows executables, both signed with a freshly minted code-signing certificate issued to a shell identity called "Work Product Inc.," are circulating as a trojanized browser installer targeting the telecom sector — a signed-binary abuse chain [T1553.002] engineered to walk past execution controls before most endpoint tools have a chance to render a verdict.
#APT28#njrat#TelecommunicationsActorsAPT28 · StrontiumIOCf3 · i3 · d3 · u1MITRE6IndustriesTelecommunications
C&CMembersMay 26, 2026, 10:47 (UTC+9)Spring Dragon Hides SQL Implant in Signed Netease Emulator, Fools All 76 AV Engines
A 24-megabyte Windows executable presenting as the legitimate Netease MuMuPlayer Android emulator has cleared every antivirus engine that examined it — all 76 of them — while simultaneously triggering a YARA rule identifying byte patterns consistent with the SKIP-2.0 SQL Server authentication-bypass implant. The binary carries a valid, unrevoked DigiCert-rooted code-signing certificate issued to Netease Interactive Entertainment Pte.
#SpringDragon#wmi_ghost#EducationResearch#TechnologyActorsSpring Dragon · Lotus BlossomIOCf2 · i0 · d4 · u1MITRE4IndustriesEducation & Research · Technology
C&CMembersMay 26, 2026, 10:27 (UTC+9)Two DigiCert Certificates, 16 Malicious Binaries, Nine Months Unrevoked
Sixteen Windows executables bearing currently-valid DigiCert G4 code-signing certificates have been circulating across Chinese-language software distribution channels since at least August 2025, impersonating disk-cleaners, QQ-cleanup utilities, zip tools, and browser-guard products — a signed-binary abuse chain [T1553.002] that walks past Windows SmartScreen and suppresses the heuristic engines that most enterprise endpoints rely on.
#TA511ActorsTA511 · MAN1IOCf26 · i8 · d3 · u3MITRE4
C&CMembersMay 24, 2026, 17:57 (UTC+9)Six Shell Companies, One Builder: DigiCert Certs Fuelled 14-Month Signed-Malware Run
Thirty-four Windows executables carrying valid DigiCert Trusted G4 Code Signing certificates — each issued to a distinct Chinese company identity — have been circulating since October 2024, disguised as consumer PC-utility software: file cleaners, memory optimisers, browser protectors, and QQ-related tray applications. The signing identities rotate. The build toolchain does not.
#FIN6#TA428#lockergoga#ncctrojan#icedidActorsFIN6 · Skeleton SpiderIOCf34 · i13 · d11 · u10MITRE23
C&CMembersMay 24, 2026, 14:51 (UTC+9)APT28 Deploys Validly Signed Chrome Fake, Gets Zero Detections
A 4-megabyte Windows executable masquerading as Google Chrome is circulating with a valid, unexpired Google LLC code-signing certificate — and every one of the 76 antivirus engines that examined it returned a clean verdict. That single data point, drawn from CTX Team's analysis of a cluster attributed to APT28 (also tracked as Fancy Bear, Forest Blizzard, and approximately 17 other aliases), captures the operational logic of the entire campaign: when a binary carries a legitimate certificate…
#APT28#GovernmentActorsAPT28 · StrontiumIOCf2 · i1 · d3 · u6MITRE4IndustriesGovernment
C&CMembersMay 24, 2026, 14:38 (UTC+9)WHQL-Signed Driver Blinds EDR a Year Before Crypto Theft Wave
A 34-kilobyte Windows kernel driver — signed with a legitimate Microsoft Hardware Compatibility Publisher certificate, bearing Safetica copyright strings, and detected by exactly two of 76 antivirus engines — was quietly staged on victim systems as early as May 2025. Nearly a year later, a coordinated wave of credential stealers, clipboard hijackers, and browser wallet harvesters began appearing in the wild, all beaconing to a two-IP cluster in a small, recently allocated autonomous system.
#TA428#WizardSpider#pythonstealer#vulcanActorsTA428 · ThunderCatsIOCf25 · i3 · d1 · u9