FILEMembersAug 13, 2026, 22:37 (UTC+9)Fake Anti-Cheat Installer Hides Beacon Behind China Unicom, CDN Certs
The most concrete artefact in this record is a single file: an installer named ACE-Setup.exe, signed end-to-end under a valid DigiCert-anchored chain running from ACEVILLE PTE LTD through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert Trusted Root G4. Its product string reads "Anti-Cheat Expert," and its embedded file paths reference two specific games — Delta Force and ABInfinite — placing the binary inside the exact directory structure…
#Confucius#beaconmalware#codesigningabuse#ChinaUnicom#CDNimpersonation#anti-cheatsoftware#gamingsector#TLScertificateabuseActorsConfuciusIOCf4 · i10 · d0 · u0
FILEMembersAug 12, 2026, 14:41 (UTC+9)15-Year-Old Sality Worm's TLS Fingerprint Ties to Tofsee C2
A Windows binary that first surfaced in mid-2010 is still being resubmitted for scanning as recently as October 2025, and its TLS behaviour trips a crowdsourced intrusion-detection rule built for an entirely different malware family. The sample is labelled trojan.sality/badcrypt and flagged by 57 of 76 engines, placing it squarely in the Sality file-infector lineage — an old, well-understood worm chassis.
#Sality#Tofsee#JA3fingerprint#clippermalware#USBpropagation#C2infrastructure#polymorphicpacker#commoditymalwareActorsSalty Spider · KuKuIOCf13 · i2 · d5 · u4MITRE32RegionsBD
FILEMembersAug 10, 2026, 06:52 (UTC+9)Mining-Themed Certificate Emerges as Prometei Files Go Quiet
The freshest artefact in this collection window is not a payload — it is a single IP address, 31.56.209.100, sitting on AS 209373 and carrying a Let's Encrypt certificate whose subject line reads corvusxmr.live. That domain, and its companion mine.corvusxmr.live and www.corvusxmr.live, describe themselves in the certificate's own subject-alternative-name field as Monero-mining infrastructure.
#OilRig#APT34#Prometeibotnet#Monerocryptomining#Let'sEncryptcertificate#telecommunicationssector#malwareattribution#command-and-controlinfrastructureActorsOilRig · APT34IOCf2 · i1 · d0 · u0MITRE8IndustriesTelecommunications
FILEMembersAug 9, 2026, 11:05 (UTC+9)One Certificate Signs Launcher, App, and Repair Tool in 3 Minutes
A single code-signing certificate — issued to SPRING (SG) PTE. LTD through the DigiCert Trusted G4 Code Signing chain — covers three functionally distinct Windows binaries: a launcher, an installed application, and a self-repair utility, all signed between 06:04 and 06:07 AM on August 2, 2026. That three-minute spread across three separate files is the most concrete fact in this record, and it reads less like three developers reaching for the same certificate and more like one build pipeline…
#codesigningcertificateabuse#DigiCert#Zenlayer#TLScertificatereuse#APT28misattribution#IcedID#maliciousfilehashes#governmentsectortargetingActorsAPT28 · StrontiumIOCf5 · i6 · d0 · u0MITRE38IndustriesGovernment
FILEMembersAug 9, 2026, 01:56 (UTC+9)Fake Root CA Signs Pirated KMS Activation Tools
Four Windows activation cracks distributed under the KMSpico and AutoKMS names carry an identical code-signing chain — but the authority that issued it isn't Sectigo, DigiCert, or any of the trust roots Windows ships with. It's "@ByELDI Certificate Authority," a self-manufactured root the operators built themselves, and every certificate under it fails Windows' own validation check.
#KMSpico#AutoKMS#codesigningabuse#self-signedcertificate#piratedsoftware#dynamicDNS#anti-analysistechniques#PatchworkActorsPatchwork · ChinastratsIOCf14 · i1 · d1 · u1MITRE51
FILEMembersAug 9, 2026, 00:27 (UTC+9)One Code-Signing Certificate Covers 14 WaveBrowser Bundleware Files
A single leaf certificate — serial 09 D7 7A 45 C1 C0 97 55 AE 3E 7A 51 53 98 3C 03, issued to "Wavesor Software (Eightpoint Technologies Ltd. SEZC)" under the DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 chain — signs all fourteen core binaries CTX Team has catalogued for a browser-and-updater bundle marketed as WaveBrowser and its companion SWUpdater service.
#codesigningcertificateabuse#bundleware#WaveBrowser#SWUpdater#PUA/adware#sandboxevasion#Authenticodetrust#misattributionActorsAPT28 · StrontiumIOCf16 · i1 · d0 · u0MITRE9IndustriesEducation & Research
FILEPublicAug 8, 2026, 23:59 (UTC+9)Signed Process Hacker Driver Now Anchors a Four-Stage Attack Chain
A signed kernel driver that Microsoft's own trust chain still vouches for is quietly doing double duty as a privilege-escalation primitive, and it is not travelling alone. The newest indicators added to a long-tracked Process Hacker 2 file set — both the x86 and x64 builds of kprocesshacker.sys (0f97f6d53fff…, 70211a3f9037…) — fire the LOLDrivers-catalogued rule PUA_VULN_Driver_Wj_Kprocesshacker_7021 despite carrying a fully valid DigiCert code-signing chain.
#ProcessHacker#BYOVD#kprocesshacker.sys#LOLDrivers#NirSoft#credentialtheft#signedmalware#kernelprivilegeescalationActorsRoyal Ransomware · Team OneIOCf35 · i0 · d0 · u0IndustriesGovernment
FILEPublicAug 8, 2026, 19:48 (UTC+9)One Trojan Sample Shows Full Evasion Playbook, No Campaign in Sight
A Win32 executable currently flagged by 61 of 76 antivirus engines packs a textbook sandbox-evasion triad — checking for an attached debugger, reading the CPU clock directly, and inspecting the CPU model string — into a single unsigned dropper that has circulated under at least four unrelated decoy filenames since 2016. What makes the sample newsworthy is not a hosting cluster or a signing certificate; there is neither.
#trojan.python/fkuk#stitchmalwarefamily#sandboxevasion#WMIdiscovery#HolyWater#StormCloud#persistencetechniques#lurefilenamesActorsHolyWater · Storm CloudIOCf1 · i0 · d0 · u0IndustriesEducation & Research
FILEMembersAug 5, 2026, 11:49 (UTC+9)Pirated Windows Activator Bundle Hides Shared Base64 Execution Trick
A "Microsoft Activation Scripts" archive built to bypass Windows and Office licensing is now doubling as a delivery mechanism for base64-encoded PowerShell payloads — and the same authoring fingerprint shows up in two structurally different file types inside the same drop. Eight of nine files tied to this indicator set carry file paths referencing "MAS/Separate-Files-Version" or "MAS/All-In-One-Version-KL," all first appearing within a 48-hour window between July 4 and July 6, 2026.
#TA505#rockloader#hacktool.autokms#hacktool.kmsauto#base64PowerShellexecution#KMSactivationpiracy#WindowsOfficelicensing#.winTLDDNScallbackActorsTA505 · Hive0065IOCf10 · i1 · d0 · u0MITRE13
FILEMembersAug 4, 2026, 13:47 (UTC+9)Validly Signed uTorrent Installer Hides Trojan.Offercore
An executable calling itself utorrent_installer.exe carries a fully valid four-tier code-signing chain — BitTorrent Inc, chained up through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 to DigiCert Trusted Root G4 — and yet 18 of 76 engines still flag it as trojan.offercore/r783575. That combination is the story here: not a forged certificate, but a genuine one riding on top of a payload the security industry has learned to distrust.
#trojan.offercore#code-signingabuse#uTorrent#anti-sandboxevasion#CloudFrontinfrastructure#P2Ptrafficmimicry#adware/PUP#TLScertificatespoofingIOCf28 · i4 · d2 · u0MITRE48RegionsAD · AE · AL · AMIndustriesChemicals · Commercial Services · Construction
FILEMembersAug 3, 2026, 21:49 (UTC+9)Old Allaple Worm Label Reused on Adobe-Masquerading HTML Droppers
Three HTML files carrying VirusTotal's family label "trojan.allaple" — 1102b8a9933b2191f1b80bd9bc478f301536216332ddf2986d3ffc792474be3d, 7768dae586920feac88943b260caa4f9a26bd357603d81517431d38f5e026594, and eb333a956be00c99c0d2523fabbea40f08ce65f5120e2744a24a5fb3abbfa3b7 — were submitted between April and August 2024, and two of them stage themselves under file paths built to look like legitimate Adobe software.
#Allaple#HTMLdropper#masquerading#embeddedJavaScript#sandboxevasion#AT&Tinfrastructure#Germanresearchnetwork#malwarefamilyreuseIOCf33 · i34 · d0 · u0MITRE24RegionsUSIndustriesRetail
FILEMembersAug 2, 2026, 05:49 (UTC+9)Fake Shipping Documents Deliver AgentTesla Stealer Under Five Packers
The payload doesn't look like malware when it lands in an inbox. It looks like a vessel particulars sheet — "MV TBN SHIP PARTICULARS.docx.exe," "SHIP PARTICULARS - MV OSTC01.xlsx.exe," "MV PACIFIC ENDEAVOR V2202 PARTICULARS I.docx.exe." Each of those alternate filenames belongs to the same 490KB Windows executable, a double-extension trick that hides an EXE behind a familiar Word or Excel icon — a lure built for whoever in a shipping or freight-forwarding chain is used to receiving cargo…
#AgentTesla#spear-phishing#maritimeshippinglure#double-extensionmalware#.NETobfuscation#SMTPexfiltration#APT29misattribution#commodityinfostealerActorsAPT29 · MinidionisIOCf9 · i0 · d2 · u0MITRE38
FILEMembersJul 31, 2026, 21:52 (UTC+9)Revoked Certs and a 1992 Timestamp: A Hacktool Kit That Won't Die
The most striking fact in this 46-file batch isn't a new malware family — it's that the tools are old, freely available, and still working. Four driver and library builds of the open-source credential-dumping tool mimikatz, including the file hashed bd177792a573f81a96c7ca9833ab7090eb8a5ea0491d1b1381efc2a5ac3f54b0, continue to carry Benjamin Delpy's original code-signing chain years after the underlying certificates were explicitly revoked by their issuers.
#mimikatz#Neshta#NirSoft#revokedcode-signingcertificates#credentialdumping#dual-usetools#LSASS#imphashActorsRoyal Ransomware · Team OneIOCf46 · i0 · d0 · u0MITRE19
FILEMembersJul 30, 2026, 13:44 (UTC+9)Four Shell Companies, One DigiCert Root: China Adware's Cert-Hopping Scheme
Fifteen Windows installers branded as GPU tuners, file-recycling tools and browser guards share a single, less advertised trait: whichever shell company's name appears on the digital signature, the trust chain underneath always resolves to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root. Over roughly a year and a half, four distinct Chinese signing identities — 成都奇鲁科技有限公司, 天津中思明达科技有限公司, 天津立方星球文化传媒有限公司 and 天津星聚时代科技有限公司 — have taken turns wearing that same trusted…
#code-signingabuse#certificaterotation#adware#PUPdistribution#ChinaTelecominfrastructure#DigiCert#domainfronting#supplychaintrustIOCf15 · i4 · d6 · u6MITRE12IndustriesTelecommunications
FILEPublicJul 28, 2026, 05:47 (UTC+9)Shared Imphash Links Pirated Keygen Trojan to Signed 2026 Installer
A single import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the thread connecting two very different-looking files: a widely pirated 2024 keygen trojan detected by 45 of 75 engines on VirusTotal, and a pair of 2026 binaries carrying a valid, unexpired code-signing certificate from a company called YAMICSOFT SOLUTIONS LIMITED.
#imphashpivoting#code-signingabuse#AgentTesla#piratedsoftwarelure#YAMICSOFTSOLUTIONSLIMITED#TA505#detectionevasion#commoditymalwareActorsTA505 · Hive0065IOCf52 · i0 · d0 · u0MITRE10RegionsAT · AU · BE · BOIndustriesTechnology
FILEMembersJul 25, 2026, 05:49 (UTC+9)Fake 'Intel Driver' Malware Checks for Sandboxes Before Striking
Before it does anything else, the binary looks around. A Win32 executable calling itself Inteldriver.exe — a name chosen to blend into a driver folder or a running-process list rather than draw attention — spends its opening moves probing the machine it has landed on for signs of a sandbox or a debugger. That single behavioural signal, carried by a file that VirusTotal shows 39 of 75 engines flagging as malicious, is the most concrete piece of tradecraft in an otherwise thin batch of 24 file…
#APT28#FancyBear#DonutLoader#sandboxevasion#processinjection#telecomsector#malwareloader#threatattributionActorsAPT28 · StrontiumIOCf24 · i1 · d0 · u1MITRE13RegionsCA · ESIndustriesTelecommunications
FILEMembersJul 24, 2026, 21:34 (UTC+9)One Domain, a Disposable Cert, and an APT29 Label That Doesn't Fit
A domain called holzbrenzii.com went live on 2025-06-23 through registrar PDR Ltd. d/b/a PublicDomainRegistry.com, sat quietly on a single hosting record for over a year, then picked up a wildcard TLS certificate with an unusually tight 89-day validity window. That's the entirety of the corroborated evidence in a threat-feed entry that also carries an APT29 attribution and a Remcos malware tag — labels that, on closer inspection, are bolted onto a record with no file, no payload, and no…
#APT29#Remcos#phishinginfrastructure#disposabledomains#TLScertificateabuse#WHOISobfuscation#threatintelligenceattribution#commoditymalwareActorsAPT29 · MinidionisIOCf1 · i0 · d1 · u0MITRE28RegionsAU · BA · BG · ECIndustriesBusiness Associations · Commercial Services · Engineering
FILEMembersJul 24, 2026, 13:47 (UTC+9)2008-Signed Kernel Driver Still Evades Most Antivirus Engines
A driver signed nearly two decades ago — its entire certificate chain now flagged as time-invalid — has resurfaced in a small but sharply detailed record that puts vulnerable-driver tradecraft, not infrastructure, at the center of the story. The file is WinRing0.sys, a hardware-monitoring kernel driver, and it carries a signature chain minted in 2007~2008 that has since decayed into forensic wreckage: every intermediate certificate in the Authenticode chain, from signer Noriyuki MIYAZAKI…
#BYOVD#vulnerabledriver#WinRing0.sys#kerneldriverexploitation#Turla#AkamaiCDNinfrastructure#LOLDrivers#signedmalwarecertificateabuseActorsTurla · Iron HunterIOCf2 · i4 · d0 · u0MITRE7IndustriesEducation & Research
FILEMembersJul 23, 2026, 21:51 (UTC+9)Expired Certificate Still Trusted in Four-Named Bundler
A single Win32 binary has been submitted to detection platforms 11,721 times from 3,694 distinct sources while wearing four different disguises — packaged and distributed as a Resource Hacker installer, an XMEye VMS setup file, a KeyTweak utility, and a glogg build. The file, catalogued under the threat label `adware.bundler/cppinstaller with popular names bundler, cppinstaller, and installcore, is the kind of high-volume, low-sophistication artifact that rarely gets a deep look — until you…
#code-signingcertificateabuse#adwarebundler#sandboxevasion#installcore#Bumblebeemisattribution#Hostingerinfrastructure#Let'sEncryptabuse#falseattributionActorsPatchwork · ChinastratsIOCf3 · i3 · d3 · u3MITRE8IndustriesEnergy
FILEMembersJul 23, 2026, 13:47 (UTC+9)Fifth IP Joins Huawei-Spoofing Cert Cluster in Guangdong
The file side of this campaign has gone quiet — zero new signed installers have surfaced since the last snapshot, while fifteen previously tracked hashes have dropped out of view entirely. But the network layer tells a different story. A newly observed address, 119.147.128.39, has joined a cluster of four IPs already sharing an identical TLS certificate — serial 5ace246430093aa3ef595686 — bringing the cohort to five distinct hosts spread across two /21 netblocks in Guangdong province, all…
#SaltySpider#sality#adware.softcnapp#TLScertificateimpersonation#HuaweiAppGalleryspoofing#CHINANETGuangdong#codesigningabuse#HappyPictureinstallerActorsSalty Spider · KuKuIOCf10 · i8 · d0 · u0MITRE6
FILEMembersJul 21, 2026, 13:40 (UTC+9)Bright Data's EarnApp Signing Chain Split to Smuggle a Stealer
A Windows installer that presents itself as EarnApp — Bright Data Ltd's consumer bandwidth-sharing client — is circulating in at least three variants that all carry a valid Bright Data Ltd code-signing chain anchored to DigiCert. Two of those variants read clean or undetected. The third, a component named net_updater32.exe dropped inside the same Program Files\EarnApp path, is classified by the C2AE sandbox as a stealer, with the malware family tag PBot attached at 50% confidence.
#EarnApp#BrightDataLtd#codesigningabuse#PBotstealer#APT28attributionmismatch#supply-chainmasquerade#PUPdomainC2#certificateinfrastructureActorsAPT28 · StrontiumIOCf92 · i9 · d44 · u6MITRE4IndustriesCommercial Services
FILEMembersJul 20, 2026, 21:46 (UTC+9)vjw0rm Worm's Full Dropper Chain Resurfaces Five Years Later
Nine file indicators tied to the vjw0rm worm family let CTX Team reconstruct, almost stage by stage, how this decade-old commodity malware still moves through a target environment in 2026: a booby-trapped Windows shortcut hands off to a batch script, which drops an AutoIT-compiled payload dressed up as a core Windows process, which then calls home to a free dynamic-DNS domain.
#vjw0rm#TA2541#OperationLayover#AutoITmalware#dynamicDNSabuse#processmasquerading#manufacturingsectorThailand#LNKdropperActorsTA2541 · Operation LayoverIOCf9 · i0 · d0 · u2RegionsTHIndustriesManufacturing
FILEPublicJul 20, 2026, 05:35 (UTC+9)Expired Certificate Still Signs Circulating UltraSurf-Branded Binary
A Win32 binary distributed under the UltraSurf and Ultrareach brand names — tools historically marketed as anti-censorship proxy utilities — carries a code-signing certificate from Ultrareach Internet Corp. that expired more than two years ago, yet the file was still circulating in submission traffic as recently as July 7, 2026.
#UltraSurf#Ultrareach#expiredcode-signingcertificate#UPXpacking#sandboxevasion#Toregress#HurricaneElectricAS6939#Glupteba2ActorsMuddyWater · TEMP.ZagrosIOCf1 · i4 · d0 · u0IndustriesWholesale
FILEMembersJul 19, 2026, 13:46 (UTC+9)'Shipping Advice' Phishing Chain Skips Fingerprints, Leans on Disposable Hosting
A phishing wave dressed up as a "shipping advice" notice is running a tight, four-step reconnaissance-and-drop chain before it ever touches a durable piece of infrastructure. The sequence — a RAR-wrapped JavaScript dropper that stages a font-disguised payload and then queries the victim's own external IP address before reaching out to a single, disposable web host — reads less like a bespoke intrusion tool and more like a lean, repeatable delivery kit.
#TA505#RockLoader#phishing#JavaScriptdropper#Namecheapinfrastructure#shippingadvicelure#IPreconnaissance#fontmasqueradingActorsTA505 · Hive0065IOCf3 · i1 · d1 · u1RegionsBD · CA · CH · DEIndustriesEnergy · Hospitality & Leisure · Support Services
FILEMembersJul 19, 2026, 05:47 (UTC+9)Reused Certificate Ties Two KMS Activators to One Build Pipeline
A pair of Windows licensing-bypass tools carrying an identical, cryptographically dead-end code-signing certificate has surfaced in a four-file cluster enriched for this feed — and the certificate is the strongest piece of evidence in the whole set. The x86 build, hashing to 50b277f770648c014924c5bf17ed94bfe149ec317a4f8b70129f3dd76e0d0a64, and its x64 counterpart, 3f2e66bbb2ed7be8655c258a2e0e43fb5bba482ae909c2c2e91865699d33b6bf, both carry a signature block naming "WZTeam" as signer, with a…
#KMSAuto++#WZTeamcertificate#codesigningabuse#WindowsDefenderevasion#UPXpacking#piracyluredomain#APT27misattribution#hacktool.kmsautoActorsAPT27 · TEMP.HippoIOCf4 · i0 · d1 · u1MITRE18IndustriesEnergy
FILEMembersJul 18, 2026, 13:56 (UTC+9)Meterpreter Loader's C2 Certificate Literally Names Itself 'C2'
A Windows binary calling itself ElevatorShellCode.exe drops a second copy of itself to C:\Windows\hy2f7vdf.exe, stalls before it does anything else, checks whether a debugger is watching, and only then calls home — to a domain whose TLS certificate lists its own Organizational Unit as "C2." Detection engines flag the loader at 44 of 75; the domain sits at a more modest 18 of 91. Neither number is what makes this campaign worth a closer look.
#UnfadingSeaHaze#Meterpreter#doghousepower#self-signedcertificate#Jordan#espionage#PowerShellstaging#sandboxevasionActorsUnfading Sea HazeIOCf9 · i0 · d1 · u2MITRE25RegionsJOIndustriesFood & Beverages · Government
FILEMembersJul 17, 2026, 14:59 (UTC+9)Fireball/Elex Adware: 14 DLLs Built in a Four-Day Cycle
A cluster of fourteen unsigned Windows DLLs — plus one companion executable — compiled between January 23 and January 26, 2017 shares a builder fingerprint tight enough to read like a single production run. The modules carry deliberately mundane names: RegKey.dll, Skytech.dll, ClearLog.dll, Packet.dll, MIO.dll, Berserker.dll, Install.dll, Lancer.dll, At.dll, and a standalone WinTooll.exe. None are signed.
#Fireball#Elex#Sasquor#adware#YARArules#maliciousDLL#MSIinstaller#sinkholedC2ActorsBarium · Wicked SpiderIOCf27 · i0 · d3 · u0MITRE43RegionsBR · PK
FILEMembersJul 17, 2026, 13:37 (UTC+9)Pikabot Loader Poses as Trend Micro DNS Module
A Win32 DLL now flagged by 60 of 78 engines as trojan.pikabot/zusy carries a product string reading "Trend Micro Osprey" and a copyright block crediting "Trend Micro Incorporated" — grafted onto a binary that is unsigned and delivers a Pikabot loader. The disguise sits alongside syscall-level anti-debug tricks and sandbox-stalling code, and the sample's associated network indicators still trip Feodo Tracker and TrickBot JA3 fingerprint rules — legacy botnet signatures riding on infrastructure…
#Pikabot#loadermalware#syscallevasion#SysWhispers#Contabohosting#FeodoTracker#TrickBotJA3fingerprint#retailsectorActorsSafePayIOCf1 · i5 · d0 · u10MITRE13RegionsUSIndustriesRetail
FILEPublicJul 16, 2026, 21:47 (UTC+9)WinPEAS-Named Binary Flags Vault Credential Hooks, Splits Sandboxes
A binary distributed under the name winPEAS.exe — one of the most widely used open-source Windows privilege-escalation enumeration tools — has turned up carrying YARA hits for Windows Vault credential objects and confidential-data-store queries, alongside two sandboxes that can't agree on what it actually is. CAPE Sandbox classifies the payload as Rhadamanthys, a well-known credential-stealing malware-as-a-service family; Zenbox instead labels it "PEASS HackTool" and flags it as a…
#WinPEAS#Rhadamanthys#APT29#WindowsVault#credentialtheft#YARAdetection#FastlyCDN#privilegeescalationActorsAPT29 · MinidionisIOCf1 · i1 · d0 · u0MITRE42RegionsCHIndustriesTechnology
FILEMembersJul 16, 2026, 13:50 (UTC+9)Cert-Mill Hides Inside Chinese Adware Supply Chain
Seventeen of nineteen enriched binaries in a newly mapped cluster of Chinese PC-utility software carry a code-signing certificate issued through the identical "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1" chain — yet the certificates were issued to at least five differently named Chinese companies, none of which appear to share ownership on paper.
#Ludashi#Chinad#Polarwind#code-signingabuse#DigiCertcertificatechain#ChinaMobileAS9808#PubNubRAT#adware/PUAsupplychainActorsAPT23 · KeyBoyIOCf37 · i4 · d4 · u2MITRE8
FILEMembersJul 15, 2026, 21:56 (UTC+9)Four Signers, One Playbook: Stolen Certs Mask VPN Trojans
A trojan-tagged VPN utility called upWire.exe carries a fully valid EV code-signing chain from WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained through GlobalSign GCC R45 EV CodeSigning CA 2020 — and still draws 29 of 74 engine detections. That contradiction sits at the center of a file set CTX Team has been tracking: nine dossiers, at least four distinct commercial signing identities, and a consistent trick underneath all of them — wrap a PUA or trojan dropper in a legitimate-looking VPN,…
#code-signingabuse#EVcertificatefraud#VPNtrojandropper#BrightData#WEILAINETWORKTECHNOLOGY#AS24429infrastructure#PBotstealer#supplychaintrustexploitationActorsCactus · Cactus Ransomware GroupIOCf49 · i9 · d33 · u8MITRE34
FILEMembersJul 15, 2026, 05:36 (UTC+9)Fake RDR2 Crack Installer Feeds DBatLoader Chain to Recycled Hosting
Two "setup.exe" installers claiming to be a FitGirl-style repack of Red Dead Redemption 2 have quietly become one of the more efficient initial-access vectors observed on public malware-sharing telemetry this year — not because the lure is novel, but because of what happens after a victim runs it. Both installers trigger a DBatLoader sandbox verdict [T1204], and one of them has been submitted 14,889 times from 3,664 unique sources, a distribution footprint that reads less like a targeted…
#DBatLoader#crackedsoftwarelure#MSILloader#VoidArachne#SilverFox#maliciousinfrastructurereuse#coinminer#IDSsignatureoverlapActorsVoid Arachne · Silver FoxIOCf10 · i4 · d2 · u0RegionsBR · PT
FILEMembersJul 13, 2026, 21:51 (UTC+9)Valid 360 EV Certificate Still Gets Flagged by AV, Trips IDS
Four Windows binaries branded as a "游戏助手" (game assistant) utility package carry a fully valid Extended Validation code-signing chain from Beijing Qihu Technology Co., Ltd. — the entity behind the 360 security and gaming ecosystem — chained through GlobalSign GCC R45 EV CodeSigning CA 2020 under certificate serial 77 D9 12 68 10 B4 7A D8 41 65 66 51. That should be the strongest trust signal a Windows binary can carry.
#Qihu360#EVcode-signingabuse#GameAssistant#adware#PUA#Steamcrackmalware#CDNcertificatesharing#misattributionActorsSnowglobe · Animal FarmIOCf10 · i7 · d0 · u0MITRE18
FILEMembersJul 13, 2026, 05:44 (UTC+9)APT33-Tagged File Catalog Is Mostly Public Webshell Kits
A record tagged to APT33 and carrying twenty file indicators turns out, on close reading, to be dominated not by a bespoke intrusion toolkit but by a corpus of long-public penetration-testing webshells — the same php-backdoor.php, cmdasp.asp, and cmd.jsp files that have circulated on GitHub archives like Webshells-main, fuzzdb-webshell, and Laudanum for well over a decade.
#APT33#webshells#YARAdetection#Laudanumtoolkit#netcat#OWASPZAP#falsepositiveattribution#AWSS3infrastructureActorsAPT33 · MagnalliumIOCf29 · i0 · d1 · u2MITRE7
FILEMembersJul 12, 2026, 21:58 (UTC+9)Free KMS Activator Ships With a Windows Defender Kill-Switch
A single cracked-software binary — sold to casual users as a free Windows activation tool — is quietly stacking four distinct evasion techniques into one package: a code-signing certificate that traces to a root nobody trusts, a UPX-packed payload that dumps itself at the original entry point, a named registry indicator for disabling Windows Defender, and anti-debug stalling behavior.
#KMSactivator#crackedsoftware#WindowsDefenderbypass#UPXpacking#code-signingcertificateabuse#GamaredonGroup#ad-frontedinfrastructure#malwareloaderreuseActorsGamaredon Group · CTIGIOCf11 · i1 · d0 · u0MITRE19IndustriesDefense
FILEMembersJul 12, 2026, 05:55 (UTC+9)Same XMRig Miner Build Resurfaces Under New Names Since 2019
A single compiled Windows binary — identified by the import-table fingerprint imphash 91ae93ed3ff0d6f8a4f22d2edd30a58e — has been circulating since June 2019, and a fresh copy of the same build turned up again as recently as June 17, 2025. Six files share that imphash, an identical rich PE header hash (50dce46bb94bc57fb0152942a792d7e2), the same PE compile timestamp (2018-09-04) and the same entry point (31187).
#XMRig#cryptominingmalware#PyInstaller#UPXpacking#RampantKittenmisattribution#commoditymalware#living-off-the-landmasquerading#malwareclusteringActorsRampant KittenIOCf8 · i1 · d0 · u0MITRE8IndustriesConsulting
FILEMembersJul 11, 2026, 21:46 (UTC+9)Trojanized Ultrasurf Sample Wraps Genuine Signature in UPX Packer
A copy of Ultrasurf — the anti-censorship proxy client used for over two decades by activists and ordinary internet users to route around national firewalls — is circulating in a UPX-packed form that nineteen of 74 engines now flag as trojan or PUA activity, even though the file still carries a genuine Ultrareach Internet Corp. code-signing chain.
#Ultrasurf#codesigningabuse#UPXpacking#MuddyWater#SilentChollima#Glupteba#TorC2#circumventiontoolsActorsMuddyWater · TEMP.ZagrosIOCf4 · i1 · d1 · u1MITRE20IndustriesGovernment
FILEMembersJul 9, 2026, 19:04 (UTC+9)Same Femo IT Hosting Block Swaps Phishing for Amadey-Stealc Crimeware
The AS214351 hosting block operated out of Femo IT Solutions Limited's German netblocks has appeared in CTX Team's tracking before, tied to rapid certificate rotation behind phishing infrastructure. This snapshot shows the same three IPs — 62.60.226.159, 196.251.107.104, and 196.251.107.130 — still live, but every one of the nine files riding them is new. The ASN hasn't moved.
#AS214351#FemoITSolutions#Amadey#Stealcv2#clipboardhijacker#Rhadamanthys#KuCointyposquat#credentialtheftIOCf9 · i3 · d0 · u10MITRE48RegionsVNIndustriesTelecommunications
FILEMembersJul 9, 2026, 10:53 (UTC+9)Fleet of Look-Alike Domains Shares One WE1 Certificate Pipeline
Five domains in a seven-domain delivery fleet — cartmask.xyz, fluxautomation.cc, microlsireqjn.com, rabbitsbird.info and silversongs.info — were issued certificates by the same Google Trust Services intermediate, "WE1," inside a roughly one-month window running from June 6 to July 7, 2026. That kind of certificate-issuance cadence, layered on top of a shared Namecheap registration workflow across three of those domains, is the signature of tooling, not coincidence — an operator standing up…
#Lummastealer#ClipBanker#KMSpicocracklure#domainfleet#GoogleTrustServicesWE1#Namecheapregistration#code-signingspoofing#cryptocurrencyclipperIOCf5 · i1 · d7 · u14MITRE52RegionsCH · KE · USIndustriesHospitality & Leisure · Technology
FILEMembersJul 8, 2026, 10:45 (UTC+9)2008-Vintage Pushdo Downloader Resurfaces With Named C2 Signatures
A Win32 downloader carrying an eighteen-year-old compile timestamp surfaced in detection feeds eleven days ago, and once it started talking, it said something specific: named Snort and Emerging Threats signatures identify its outbound traffic as Pushdo botnet check-in behaviour, not generic malware noise. The binary's PE header reads 2008-09-12; its first appearance in detection telemetry is 2026-06-27 — a gap of roughly eighteen years that is consistent with a decade-old Cutwail/Pushdo builder…
#Pushdo#Cutwail#botnetdownloader#packedPEmalware#HIVELOCITYAS29802#threatintelligencemislabeling#IDSsignaturedetection#C2beaconingActorsPinchy Spider · SodinokibiIOCf3 · i9 · d10 · u7RegionsDE
FILEPublicJul 8, 2026, 02:52 (UTC+9)One Domain Runs Both Ends of a SWIFT-Themed Malware Chain
A domain named to evoke SWIFT bank-transfer messaging, registered through Dynadot Inc on 2022-06-10, has been quietly running both ends of an intrusion chain from one machine. swift-be.com is not fronting a CDN, is not split across a constellation of look-alike names, and is not hiding behind a bulletproof host. Instead, the same domain serves a PHP check-in script at swift-be.com/roks4/gate.php and a directly named executable payload at swift-be.com/roks4/shit.exe — both sitting under the…
#GorgonGroup#Subaat#swift-be.com#gate.phpC2#commoditydropper#Let'sEncryptcertificateabuse#manufacturingsectorBangladesh#PEpackerevasionActorsGorgon Group · SubaatIOCf2 · i0 · d1 · u2RegionsBDIndustriesManufacturing
FILEMembersJul 7, 2026, 18:55 (UTC+9)Batch-Registered Domains Mimic Baixaki to Push COMODO-Signed Adware
Three domains registered in the same transaction, at the same registrar, at the same second, are doing the work of an entire distribution network for a low-detection installer campaign. The apex domain, baixakialtcdn.com, and its two operational subdomains — os.baixakialtcdn.com and os2.baixakialtcdn.com — were all created through PDR Ltd.
#DealPly#PUP#Baixakiimpersonation#AzionCDN#COMODOcodesigning#domainsquatting#Brazil#bundledinstallerIOCf8 · i2 · d3 · u5MITRE34RegionsBR
FILEMembersJul 7, 2026, 11:09 (UTC+9)Six-Year-Old Emotet Macro Doc Still Evades a Third of AV Engines
A macro-enabled Word document that first surfaced in October 2020 is still doing exactly what it was built to do: get opened, auto-run its embedded VBA project, and quietly hand off to a follow-on payload — while nearly a quarter of the antivirus industry either misses it outright or can't parse the file at all. The sample, carrying the threat label "downloader.w97m/emotet," draws 46 flags out of 77 engines and a unanimous 3-for-3 malicious verdict across three separate sandboxes.
#Emotet#macrodownloader#VBAmalware#phishingattachment#sandboxdetection#GoDaddyhosting#Microsoft365#TA542ActorsEmotet Group · TA542IOCf4 · i0 · d2 · u4RegionsAT
FILEMembersJul 6, 2026, 19:21 (UTC+9)A 2008 Domain Wakes Up on a Contabo Asia IP
A certificate serial number is not supposed to outlive a decade of digital abandonment. But that is exactly what has happened to carltonbaggies.com, a domain registered through Bluehost Inc. back on 2008-02-19 — 6,698 days of registration history that included no meaningful hosting activity worth tracking, according to the record available to CTX Team.
#Silence#ContractCrew#WhisperSpider#domainreactivation#TLScertificateabuse#spearphishingattachment#drivermasquerading#ContaboAsiainfrastructureActorsSilence · Contract CrewIOCf7 · i2 · d6 · u2MITRE43
FILEMembersJul 6, 2026, 02:52 (UTC+9)Fake 'Elden Ring' Launcher Fools Sandboxes, Not 52 AV Engines
A binary calling itself "Elden Ring.exe" — and, in an alternate build, "Launcher Elden Ring.exe" — is not a cracked copy of a hit fantasy RPG. It is a dropper that static engines recognize almost immediately and dynamic sandboxes almost entirely miss, a split that is the real story here. Fifty-two of 75 antivirus engines flag the file (hash 32f34fb30fd47ab761e94306bc30432cd41d67309ab1e6b2599be2d70d3bd285) as malicious, carrying the label trojan.rancor/usblek26 along with community tags of…
#Snowglobe#AnimalFarm#babarbackdoor#Thailandtelecom#sandboxevasion#malwaredropper#koodgame.com#espionagemalwareActorsSnowglobe · Animal FarmIOCf3 · i0 · d1 · u0MITRE22RegionsTHIndustriesTelecommunications
FILEMembersJul 5, 2026, 16:36 (UTC+9)One Softonic EV Signature, Two Unrelated Malware Installers
A single Sectigo EV code-signing certificate — issued to SOFTONIC INTERNATIONAL SA and timestamped 04:20 PM on 06/24/2025 — sits behind two structurally unrelated Windows installers now circulating under the names of Hamachi, Termux, a casual game called "bee-movie-game," and a reminder utility called "minireminder." The binaries, catalogued as 68e4a2bfe728081eb1a84369f7dbad74c12c06a306cd5ad974ded8df3283a2ad and e8c438babbc09306f7a903f6e8f78b59ed395c81d541417c1b009b45bdc77040, share the…
#code-signingabuse#SectigoEVcertificate#Softonic#adware.offercore#CloudFrontinfrastructure#installermasquerading#DustSquad#lummastealerActorsDustSquad · APTC34IOCf2 · i0 · d1 · u2MITRE16RegionsEC
FILEPublicJul 1, 2026, 17:17 (UTC+9)NanoCore RAT Sample Adds Sandbox-Evasion Tricks, Beacons to Dead DuckDNS Domain
A 280-kilobyte Windows executable carrying the internal name En2m7acq.exe — tagged internally as product "Unemawermaq" — has surfaced with a detection profile that reads less like a novelty and more like a warning about how far anti-analysis engineering has trickled down into everyday commodity malware. Fifty-nine of 77 antivirus engines flag the file outright, and all three sandboxes that processed it — VMRay, C2AE, and Zenbox — converge on the same verdict: a NanoCore Remote Access Trojan,…
#NanoCoreRAT#Codoso#APT19#DuckDNS#sandboxevasion#dynamicDNSC2#commoditymalware#espionageattributionActorsCodoso · Sunshop GroupIOCf2 · i0 · d1 · u0MITRE17
FILEMembersJun 30, 2026, 10:01 (UTC+9)Decade-Old njRAT Stub Pair Resurfaces as 'Black Atlas' Campaign
Two unsigned Windows executables sharing an identical import-table hash and an identical compile timestamp are the spine of a njRAT cluster that a threat feed has only just begun surfacing under the label "Operation Black Atlas" — despite the underlying files dating to October 2014. The binaries, catalogued as c81b26e4b7cc5d3b3ab7aedb9da06b6b1cf863a2d475ac12f590b5b2a18e515a (internally named Stub.exe, 96KB) and b85913770053b4ac5ba69766924f6aab10e1ccc346bfb09571debdbd1bf37727 (internally named…
#njRAT#OperationBlackAtlas#dynamicDNS#No-IP#retailsector#malwarecluster#commandandcontrol#imphashanalysisActorsOperation Black AtlasIOCf5 · i0 · d1 · u0MITRE33RegionsUSIndustriesRetail
FILEMembersJun 29, 2026, 21:46 (UTC+9)Dormant Domain Wakes Days Before New Invoice-Lure Malware Wave
Seven months after a Namecheap registrant quietly stood up xingtialai.com, the domain's operators finally bothered to secure it: a Let's Encrypt certificate was issued for the site on 2026-06-23, and the origin server behind it picked up its own certificate two days earlier, on 2026-06-21. Within a week, on 2026-06-29, two brand-new files — an invoice-themed .NET loader and the RAR archive that appears to have delivered it — surfaced carrying anti-sandbox timers and debugger checks.
#credentialtheft#browsersecretsstealer#invoicelure#anti-sandboxevasion#xingtialai.com#OVHinfrastructure#KeyLogger#MicroClipIOCf21 · i1 · d1 · u0MITRE38RegionsAU · CN · DE · HUIndustriesSupport Services · Telecommunications
FILEPublicJun 29, 2026, 05:56 (UTC+9)Dormant Domain Aged Three Years to Target Iraq's Auto Sector
##A Three-Year Wait to Strike: How a Dormant Domain Became the Gateway for Iraq's Automotive Sector Attack Sometime in July 2023, an operator registered datausercenterphx.com through Namecheap and then, apparently, did nothing with it. No certificate was issued. No payload was staged. The domain sat parked against Namecheap's own forwarding nameservers — dns1.registrar-servers.com and dns2.registrar-servers.com — accumulating age and, with it, the kind of passive domain reputation that…
#domainaging#Iraq#automotivesector#processinjection#datadestruction#sandboxevasion#Contaboinfrastructure#downloaderIOCf11 · i2 · d1 · u2MITRE26RegionsIQIndustriesAutomotive