FILEMembersSep 23, 2026, 14:55 (UTC+9)A 21-Kilobyte Worm Stalls the Sandbox, Then Mails Itself Onward
The only indicator in this record with real telemetry behind it is a 21-kilobyte Windows executable that arrives as an email attachment, checks whether a debugger is watching it, deliberately stalls before doing anything, and then re-mails itself to the next victim. Everything else attached to this record — 40 other file hashes, seven IPs, eight domains, all filed under a "Lazarus Group" actor tag — carries no meaningful telemetry at all.
#LazarusGroup#MyDoom#mass-mailingworm#SMTPpropagation#sandboxevasion#processmasquerading#Incapsulainfrastructure#threatintelhygieneActorsLazarus Group · Hastati GroupIOCf41 · i7 · d8 · u0RegionsCH · CN · JO · USIndustriesGovernment · Retail · Support Services
FILEMembersSep 22, 2026, 22:34 (UTC+9)Recycled Sectigo Certificate Links Loader and Banking-Trojan Payload
The same revoked leaf certificate — serial 00 8E 3E 9A 2F E7 3C 91 98 5B 4F 90 D5 95 77 CD 6C, issued under the name MASTER LIM LTD and chained through COMODO RSA Code Signing CA up to Sectigo (formerly Comodo CA) — is stamped on two files that sit at opposite ends of a delivery chain: an NSIS self-extracting installer and the banking-trojan DLL it ultimately drops.
#TA505#LDPinchbanker#Sectigocodesigningabuse#NSISinstaller#VBScriptstager#sandboxevasion#DGAdomains#bankingtrojanActorsTA505 · Hive0065IOCf5 · i0 · d2 · u4MITRE37RegionsCH · USIndustriesRetail · Support Services
FILEMembersSep 22, 2026, 14:47 (UTC+9)5KB Fake 'update.exe' Stager Ties to Tomiris/YoroTrooper Espionage
A stager built to pass as nothing more than a routine Windows update file is barely large enough to hold its own icon — five kilobytes of packed .NET code, unsigned, dropped straight into C:\Windows\Temp\update.exe. Despite the size, 55 of 76 antivirus engines flag it, and the record ties the sample (4f237b5a…) to the espionage-focused Tomiris and YoroTrooper clusters.
#Tomiris#YoroTrooper#AgentTesla#.NETstager#anti-debuggingevasion#Let'sEncryptcertificateabuse#VDSINAVPShosting#espionagemalwareActorsTomiris · YoroTrooperIOCf1 · i1 · d0 · u1MITRE12RegionsCH · JO · USIndustriesGovernment · Retail · Support Services
FILEMembersSep 21, 2026, 14:31 (UTC+9)One 2009 Compile Job Is the Only Real Link in 'Klovbot' Cluster
Everything else in this record is décor around one hard fact: two of the five files carried under a shared feed label share not just a detection verdict but an identical import table hash, an identical rich-header fingerprint, and an identical PE compile timestamp of January 14, 2009. That is not coincidence — it is proof that whoever built the Hiloti/Mufanom downloader compiled it once and shipped it out twice, once packaged as a standalone executable and once as a dynamic-link library, both…
#Klovbot#Hiloti#Mufanom#Buzus#Prolaco#Renos#commoditymalware#malwareclusteringIOCf46 · i1 · d6 · u2MITRE48RegionsUSIndustriesEngineering
FILEMembersSep 21, 2026, 07:04 (UTC+9)Fake Adobe Audition Patch Fans Out Into Two Trojan Families
A pirated license patch for Adobe Audition is doing more work than a typical cracked-software lure. Once a victim runs the fake "Adobe Audition Patch v24.exe," the package drops from an identical temporary-folder fragment — u2pvkyr3.1xh\Patch-Activated\ — into two forensically distinct payloads that VirusTotal resolves under entirely different threat labels: trojan.swisyn/gosys on one branch, trojan.autoit/nymeria on the other.
#crackedsoftwarelure#AutoITdropper#Doeneriumstealer#imphashreuse#JA3fingerprint#node.exemasquerade#CommentCrew/APT1#malwaredistributionActorsComment Crew · Byzantine CandorIOCf48 · i0 · d0 · u0MITRE51RegionsGT
FILEMembersSep 19, 2026, 06:42 (UTC+9)Remcos RAT Sample Stalls Sandboxes, Checks for Debuggers
A 92-kilobyte Windows executable now flagged by 64 of 74 antivirus engines carries one of the most heavily fingerprinted commodity RATs in current circulation — and it does so with a textbook anti-analysis playbook baked in before it ever reveals its payload. The dropper, tracked here as d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867, is unsigned, packed with PEiD, and — according to three independent sandboxes that returned a unanimous malicious verdict — runs as Remcos, the…
#RemcosRAT#GorgonGroup#Subaat#sandboxevasion#anti-debugging#UACbypass#gambling-luredomains#commoditymalwareActorsGorgon Group · SubaatIOCf1 · i0 · d3 · u2MITRE11
FILEMembersSep 18, 2026, 14:36 (UTC+9)Sandbox Clears It, 26 Engines Don't: Allaple's Acrobat HTML Ruse
A dropper posing as an Adobe Acrobat DC interface resource carries the file name "index.html" and sits, according to its own embedded path reference, inside C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\index.html. Twenty-six of 77 engines on VirusTotal flag it as trojan.allaple. A single sandbox run on the same file, however, returned a "harmless" verdict at 99% confidence.
#Allaple#trojan.allaple#AdobeAcrobatDCmasquerade#sandboxevasion#staticvsdynamicdetection#MaxfonSrlnetblock#ItalyISPinfrastructure#packedPE32IOCf33 · i41 · d0 · u0MITRE12RegionsUSIndustriesRetail
FILEPublicSep 18, 2026, 06:57 (UTC+9)MuddyWater Loader Skips DNS, Curls Straight to a Bare IP
A Windows loader flagged as trojan.donut/dump by 57 of 75 engines is issuing outbound HTTP requests with a curl-style user agent straight to a numeric IP address rather than a resolved domain — a pattern four separate community intrusion-detection rules independently caught on the same sample. The same binary checks the CPU timer before running, a classic sandbox-timing test, and loads additional modules only after that check clears.
#MuddyWater#Seedworm#donutloader#C2tobareIP#sandboxevasion#HostSailorLtd#espionage#in-memoryexecutionActorsMuddyWater · TEMP.ZagrosIOCf3 · i1 · d0 · u1MITRE36RegionsCN
FILEMembersSep 17, 2026, 14:29 (UTC+9)Phorpiex Drop Point Holds Steady as Yemeni Telecom ASN Absorbs New Churn
The most interesting fact in this snapshot of a long-running Phorpiex/Kadrbot cluster isn't a new payload — it's what didn't change. The bare-IP delivery host that anchored CTX Team's earlier look at this cluster, 185.215.113.84, still serves the same six sequentially numbered /twizt/1 through /twizt/6 paths it did before, sitting at 16 of 89 security-vendor detections on VirusTotal.
#Phorpiex#Kadrbot#YementelecomASN#Seychelleshosting#bare-IPdelivery#Xmrigcryptomining#wormdownloader#maliciousfilehashesIOCf4 · i4 · d0 · u7MITRE37RegionsAF · ROIndustriesHealthcare
FILEMembersSep 16, 2026, 06:44 (UTC+9)Adware Installer With Decade-Expired Cert Wrongly Tagged as Lazarus
An adware installer first signed in January 2014 is still circulating with a code-signing certificate that has been invalid for roughly a decade — and the trust chain still resolves cleanly enough that antivirus engines are split on what to do with it. The file, publicly known under the generic name Installer.exe (c5a1140f6de397ad…), carries a signature block reading "Amonetize ltd.; Thawte Code Signing CA - G2; thawte" [T1553.002], but the leaf certificate's own status field says plainly:…
#LazarusGroup#phandoor#code-signingabuse#adwarebundleware#command-and-controlinfrastructure#Amonetize#Let'sEncryptcertificate#pay-per-installActorsLazarus Group · Hastati GroupIOCf1 · i0 · d1 · u2MITRE13RegionsES · VNIndustriesTelecommunications
FILEMembersSep 15, 2026, 22:33 (UTC+9)20-File Kit Bundles Mimikatz, Revoked Driver, PrintNightmare Exploit
A 20-file dossier tracked by CTX Team reads less like a single implant and more like a toolbox someone packed once and shipped intact. At its center sits the open-source mimikatz credential dumper in its signed 2.2.0.0 release form, flanked by a kernel driver still carrying a certificate its own issuer revoked years ago, a bundled exploit module for the PrintNightmare spooler flaw (CVE-2021-1675), and five Nirsoft password-recovery utilities packed with an identical fingerprint and staged in…
#mimikatz#PrintNightmare#CVE-2021-1675#Nirsoftutilities#credentialtheft#revokedcode-signingcertificate#Sandworm#APT27ActorsSandworm · QuedaghIOCf34 · i0 · d0 · u0MITRE28RegionsBRIndustriesManufacturing
FILEMembersSep 15, 2026, 14:58 (UTC+9)A Fifteen-Year-Old Virus Still Rides a Fresh HTML Template
A Sality file infector first captured in mid-2010 is still circulating today, and the html page delivering it isn't old at all — it's a template reused just eight months apart, sitting at zero detections both times. The pairing is the real story here: a payload so well-documented that 56 of 76 engines flag it on sight, fed through a delivery artifact so unremarkable that VirusTotal's entire detection industry walks past it.
#Sality#badcrypt#salload#SaltySpider#polymorphicmalware#HTMLdropper#USBautorunspread#TofseeJA3fingerprintActorsSalty Spider · KuKuIOCf20 · i2 · d1 · u0RegionsUS
FILEMembersSep 14, 2026, 22:58 (UTC+9)One Bundler, Four Fake Names, an APT28 Label That Doesn't Fit
A single Win32 installer, 4.4 megabytes, has spent the past two years circulating under at least four different identities — a PingInfoView update, a Roblox Player installer, a Portuguese file-renaming tool called "renomear-tudo," and a Microsoft PC Manager setup package. All four are the same binary (imphash bdc39b1d…), repackaged under different display names and reused across 1,644 separate submissions from 1,438 unique sources.
#APT28misattribution#adwarebundler#codesigningcertificateabuse#malvertisingredirectinfrastructure#EnigmaProtectorpacker#pay-per-install#commoditycrimeware#Let'sEncryptcertificateabuseActorsAPT28 · StrontiumIOCf2 · i1 · d3 · u5MITRE11IndustriesUtilities
FILEMembersSep 13, 2026, 15:10 (UTC+9)Revoked EV Certificate Still Signs Fake-VPN Malware for Months
A loader-and-updater trio still carries a fully valid-looking code signature from an EV certificate that VirusTotal has explicitly marked revoked — and the operators kept building new samples under that same signing identity for roughly four months after the revocation took hold. Three files — a sideloaded DLL, its companion loader, and an updater binary that installs to C:\Windows\SysWOW64\wire\ — are signed end to end as WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained up through a GlobalSign…
#WEILAINetworkTechnology#revokedEVcertificate#wirevpnloader#VPNMasterdeceptor#BrightDataSDKabuse#codesigningabuse#fakeVPNmalware#APT15ActorsAPT15 · ROYALAPTIOCf8 · i2 · d3 · u0MITRE24IndustriesFood & Beverages
FILEMembersSep 12, 2026, 14:56 (UTC+9)Pterodo Backdoor Hides Inside Fake Blender Install Path
A Windows DLL flagged as trojan.pterodo/doina installs itself under a filepath that reads like a legitimate Blender Foundation component — C:\Program Files\Blender Foundation\Blender\A562C7DBA738DC65D3B7DEADE7FFC31D — a GUID-style filename sitting inside a real 3D-graphics software directory rather than a temp folder or a randomly generated string in %APPDATA%.
#Pterodo#Gamaredon#Shuckworm#backdoorDLL#systembinaryproxyexecution#malwaremasquerading#C2infrastructure#espionagemalwareActorsGamaredon Group · CTIGIOCf2 · i0 · d1 · u0MITRE9RegionsCH · CNIndustriesSupport Services
FILEMembersSep 12, 2026, 06:50 (UTC+9)Aged GoDaddy Domains Get Synced Certs, Front 2018 Macro Downloader
Two domains that have sat quietly under GoDaddy registration since the mid-2000s were both re-fronted with brand-new Let's Encrypt certificates within about five weeks of each other in mid-2026 — dthakar.com and elmodular.com, ages 19 and 20 years respectively, neither showing any sign of active legitimate use in that span. A third node, eatspam.co.uk, and its sole resolving address, 45.158.164.138, picked up matching certificates from the same issuer pool on an overlapping schedule.
#EmotetGroup#w97m/emodldr#macrodownloader#Let'sEncryptcertificateabuse#domainhijacking#GoDaddy#WMIexecution#recycledhostinginfrastructureActorsEmotet Group · TA542IOCf3 · i1 · d3 · u6
FILEMembersSep 10, 2026, 14:52 (UTC+9)Fake Windows Update Binary Hides Stealc Credential Stealer
A binary that calls itself wsus.exe, complete with a spoofed "AdobeReaderFlash Corporation" copyright string, has been circulating disguised as a routine Windows Update helper — and underneath the generic trojan labels most antivirus engines assign it, a named detection rule identifies the payload specifically as Stealc, a known credential-stealing family.
#Stealc#masquerading#wsus.exe#sandboxevasion#HostkeyB.V.#credentialtheft#Silence#commandandcontrolActorsSilence · Contract CrewIOCf2 · i1 · d0 · u2MITRE23RegionsCH · CN · JOIndustriesSupport Services
FILEMembersSep 9, 2026, 22:58 (UTC+9)Malware Sample Stalls to Dodge Sandboxes, Hides Behind Thin Infrastructure
A Windows executable masquerading as joduj.exe (e9e732f7…) sits idle after launch, deliberately stalling for long stretches and polling the CPU clock directly to work out whether it has landed inside a sandbox before it will do anything else. That single behavioural signature — confirmed by a malicious verdict from the Yomi Hunter sandbox and flagged by 55 of 75 engines — is the strongest piece of evidence in this case, and it maps cleanly to time-based sandbox evasion [T1497.003].
#SpringDragon#LotusBlossom#sandboxevasion#timestomping#importtableanalysis#SouthKorea#SKBroadband#espionagemalwareActorsSpring Dragon · Lotus BlossomIOCf5 · i2 · d0 · u4RegionsIN
FILEPublicSep 8, 2026, 14:33 (UTC+9)Fake KMSPico Activator Cluster Traces to Adware Builder, Not APT10
A trojanized copy of KMSPico — the pirated-software crowd's favorite "free" Windows and Office activation tool — is the lure carrying an entire adware-bundler cluster: six installers and a companion batch script, all packaged inside Nullsoft Installer (NSIS) self-extracting archives and all first seen within a roughly nine-month window spanning April 2015 to January 2016.
#KMSPico#adwarebundler#NSISinstaller#code-signingcertificateabuse#browsefox#outbrowse#RedApolloAPT10misattribution#builder-as-a-serviceActorsRed Apollo · PotassiumIOCf7 · i1 · d1 · u0MITRE21RegionsJP
FILEMembersSep 7, 2026, 14:46 (UTC+9)One TLS Certificate Ties Five Hosts to Sekisui House Impersonation
Seventeen IP addresses sit inside a single file-hash record tagged to the Allaple worm family, and fourteen of them collapse into one place: AS4713, registered to NTT DOCOMO BUSINESS,Inc. Five of those fourteen — 202.18.210.172, 202.18.210.153, 202.18.209.143, 202.18.209.144, and 202.18.209.153 — serve a byte-identical TLS certificate, serial b9f3aa6546060eaeb9b07a8fed689d8, issued by GeoTrust TLS RSA CA G1 under DigiCert, with a wildcard subject of *.sekisuihouse.co.jp.
#Allaple#AS4713#NTTDOCOMOBUSINESS#SekisuiHouseimpersonation#TLScertificatespoofing#masquerading#Japaninfrastructure#maliciousfilehashesIOCf9 · i17 · d0 · u0MITRE25RegionsUSIndustriesRetail
FILEMembersSep 5, 2026, 22:40 (UTC+9)Fake Adobe Acrobat DC Folder Hides Base64-Obfuscated URL
Three HTML files carrying the generic "trojan.allaple" label look, at first glance, like leftovers from a worm outbreak that antivirus vendors have tracked for the better part of two decades. Buried in their metadata, though, is a more specific and more current story: two of the three files were captured with internal path names placing them inside a real Adobe Acrobat DC installation tree — C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\resources\ui\index.html and C:\Program…
#Allaple#masquerading#defenseevasion#AdobeAcrobatDC#Base64obfuscation#VerizonBusiness#maliciousfilehashes#YARAdetectionIOCf33 · i11 · d0 · u1MITRE25RegionsUSIndustriesRetail
FILEMembersSep 5, 2026, 06:54 (UTC+9)A Code-Signing Chain That Fails on the Clock, Not the Crypto
A Win32 binary carrying a full COMODO-anchored code-signing chain isn't unusual — until you notice the validation failure has nothing to do with the signature itself. The file, chained through LLC "INTELEKT-SOFT" up through COMODO RSA Code Signing CA to Sectigo (formerly Comodo CA), fails verification purely because its leaf certificate's validity window — 21 September 2015 to 20 September 2016 — no longer covers the clock the verifier is checking against (35cf61c8b0…).
#Snowglobe#AnimalFarm#Sig20#babarmalware#code-signingcertificateabuse#packerevasion#command-and-controlinfrastructure#espionageActorsSnowglobe · Animal FarmIOCf1 · i0 · d2 · u0MITRE17RegionsUSIndustriesRetail
FILEMembersSep 3, 2026, 22:54 (UTC+9)Espionage C2 Domain Hides Behind Its Hosting Provider's Certificate
An espionage-linked command-and-control domain, mercadojs.com, is presenting a public face that belongs to its landlord rather than its operator. The domain resolves to a single IP address, 82.25.83.117, sitting on AS 47583 — Hostinger International Limited — but the certificate served from that address is issued to "hostinger.com" with a wildcard subject-alternative-name covering *.hosting24.com, both of them Hostinger's own branded properties, not mercadojs.com.
#mercadojs.com#OperationGhoul#Hostinger#Let'sEncrypt#Switzerland#Jordan#command-and-control#espionageActorsOperation GhoulIOCf1 · i1 · d1 · u1MITRE13RegionsCH · JOIndustriesGovernment · Support Services
FILEMembersAug 31, 2026, 23:10 (UTC+9)RuntimeBroker Impersonator Rides a Frozen C2 Backbone
A dropper carrying the internal name WmiPrvSE and exported to disk as runtimebroker.exe has surfaced with a full anti-analysis stack — debugger checks, deliberate execution stalling, and a Zenbox sandbox verdict of MALWARE/EVADER at 88% confidence — while the infrastructure behind it has not moved at all. The three IP addresses tied to this activity sit on the same autonomous system, AS214351, registered to Femo IT Solutions Limited, that CTX Team has already tracked in earlier coverage of this…
#WizardSpider#RuntimeBrokermasquerading#AS214351#FemoITSolutions#C2infrastructure#packeddropper#SwitzerlandJordantargeting#TLScertificateimpersonationActorsWizard Spider · Grim SpiderIOCf1 · i3 · d0 · u6MITRE34RegionsCH · JOIndustriesFood & Beverages · Government · Support Services
FILEMembersAug 30, 2026, 22:41 (UTC+9)Revoked 2011 Certificate Still Fools Users into Trusting AutoIt Loader
A code-signing certificate that GlobalSign revoked years ago is still doing work for its original signer's name — just not for the original signer's purpose. In a file cluster CTX Team has been tracking, a binary that presents itself as the legitimate AutoIt v3 scripting runtime carries a signature chain rooted in AutoIt Consulting Ltd, issued through GlobalSign ObjectSign CA back in May 2011 and expired by design in 2014.
#LazyScripter#NetWireRAT#AutoIt#code-signingcertificateabuse#dynamicDNS#sandboxevasion#GlobalSign#commoditymalwareActorsLazyScripterIOCf22 · i1 · d1 · u1MITRE27
FILEMembersAug 29, 2026, 14:41 (UTC+9)Fake Microsoft Installer Trips Three Rival Malware Signatures at Once
A loader dressed up as Wextract, the innocuous Windows component that unpacks self-extracting installer packages, carries a Microsoft Corporation signer chain that fails validation outright — and once analysts looked past the broken signature, the binary turned out to simultaneously trip YARA rules built for three unrelated malware lineages: an Andariel-linked packer signature, a Cobalt Strike beacon-loader rule, and a Formbook anti-hook bypass routine.
#SilentChollima#Andariel#Stonefly#DTrack/Injuke#CobaltStrike#Formbook#code-signingmasquerade#retailsectortargetingActorsSilent Chollima · AndarielIOCf1 · i0 · d2 · u10MITRE16RegionsCN · USIndustriesRetail
FILEMembersAug 25, 2026, 22:44 (UTC+9)Fake KMS Activator's Broken Signature Feeds a DynDNS Downloader Chain
The file at the center of this case doesn't try to hide what it claims to be. It presents itself as KMSoffline, a real, widely pirated Windows-activation utility, and ships inside folder paths named "activador office," "KMSoffline v2.3.5 RU EN," and "KMS Tools Portable 2022" — the exact packaging a user would expect from a torrented activation bundle.
#APT27#KMSoffline#code-signingabuse#PowerShelldownloader#DynDNSbeaconing#Thailandtransportationsector#disposabledomaininfrastructure#sandboxevasionActorsAPT27 · TEMP.HippoIOCf20 · i1 · d1 · u4MITRE53RegionsTHIndustriesTransportation
FILEMembersAug 24, 2026, 22:33 (UTC+9)Five-Year-Old Emotet Macro Downloader Resurfaces in 2026 Tracking Window
A Word document that first surfaced on VirusTotal in October 2020 is still doing exactly what it was built to do: open itself, drop a second file, and run it. The sample — internally named Attachment-5598.doc, a naming pattern consistent with an email-lure delivery method [T1566.001] though no delivery URL or mail header sits in this record to confirm that path — carries the tags "auto open," "creates OLE objects," "contains office macros," and "runs a file it drops to disk." That is not a…
#Emotet#TA542#macrodownloader#PowerShelldownloader#Let'sEncryptcertificates#phishingdocument#educationsector#governmentsectorActorsEmotet Group · TA542IOCf4 · i1 · d2 · u0RegionsRO · USIndustriesEducation & Research · Government
FILEMembersAug 24, 2026, 14:46 (UTC+9)Severity-100 Espionage Alert Unravels Into Two Pirated Activators
A threat-feed record carrying top severity and an attribution to Gamaredon Group turns out, once the underlying files are pulled apart, to rest on nothing more exotic than two pirated Windows activation tools — one wrapped in a code-signing certificate whose trust chain dead-ends at an unrecognized root, the other an unsigned console build tied to a well-documented KMS emulator kit.
#GamaredonGroup#AutoKMS/KMSAuto#code-signingabuse#UPXpacking#anti-analysistechniques#threat-feedattribution#piratedsoftware#RatiborusKMSemulatorActorsGamaredon Group · CTIGIOCf3 · i0 · d0 · u0MITRE17IndustriesGovernment
FILEMembersAug 24, 2026, 06:37 (UTC+9)Fake Invoice Lure Ships Same Downloader in PowerShell and JavaScript
A purchase-order-themed archive built to impersonate a signed PDF invoice — PO_400269712_Signed_Copy.pdf.txz — has turned up alongside a matching downloader kit that ships the same payload twice: once as a PowerShell script and once as JavaScript, both carrying the identical internal name sleestak_payload_1.bin, both exactly 64KB, and both first observed on the same day, 2026-08-12, with zero antivirus detections on either.
#TA505#Hive0065#rockloader#PowerShelldownloader#JavaScriptdownloader#manufacturingsectorphishing#SouthAfricahostinginfrastructure#purchaseorderlureActorsTA505 · Hive0065IOCf7 · i1 · d1 · u2RegionsDE · IN · IT · THIndustriesManufacturing
FILEMembersAug 22, 2026, 14:52 (UTC+9)A Five-Minute Certificate, a Decade-Old Encryptor, One Shared Record
A domain flagged for phishing and fraud, atlanticinsulationservices.co.uk, was issued a TLS certificate on August 10, 2026 that expired five minutes after it was cut — valid from 11:17:47 to 11:22:47 UTC. That is not the certificate of a working website; it reads like automated infrastructure standing itself up, existing, and disappearing before an analyst could even resolve it in a browser.
#Rtm#Cerber#CryptoWall#ransomware#TLScertificateabuse#Let'sEncrypt#phishinginfrastructure#retailsectorActorsRtmIOCf1 · i6 · d24 · u6MITRE22RegionsUSIndustriesRetail
FILEMembersAug 19, 2026, 07:10 (UTC+9)Salat Stealer Domains Share TLS Cert Cadence Despite 2-Year Gap
The most concrete signal in this update to the Snowglobe-linked campaign isn't a new payload capability — it's a provisioning pattern. Two command-and-control domains, sa1atik.cn and websalat.top, were issued matching Google Trust Services "WE1" wildcard certificates within an 18-day window this summer, despite the domains themselves being registered nearly two years apart.
#Snowglobe#SalatStealer#Vidar#Babar#wildcardTLScertificate#Cloudflareinfrastructure#UPXpacking#credentialtheftActorsSnowglobe · Animal FarmIOCf1 · i2 · d2 · u2MITRE10RegionsCN · DE
FILEMembersAug 18, 2026, 14:51 (UTC+9)Cracked SQLi Dumper Tool Doubles as BitRAT Delivery Vehicle
A pirated copy of a well-known penetration-testing utility is being used as bait to plant a commodity remote-access trojan on victim machines, according to indicators CTX Team has reviewed. Two Win32 executables in this cluster present themselves as a "cracked" release of SQLi Dumper v8.5, a SQL-injection scanning tool popular with penetration testers and opportunistic attackers alike, while sharing the same packing signature and a matching set of anti-analysis checks.
#BitRAT#SQLiDumper#BlueBottle#crackedsoftwarelure#Italyfoodandbeveragesector#commodityRAT#self-signedTLScertificate#anti-analysistechniquesActorsBlueBottle · Opera1erIOCf4 · i1 · d0 · u1MITRE23RegionsITIndustriesFood & Beverages
FILEMembersAug 16, 2026, 23:04 (UTC+9)Signed Nmap Ncat Build Disguised as Windows Shell File
Eight files pulled into a single record span two decades of Windows malware, but the one that earns the headline is neither the biggest ransomware name in the batch nor the newest. It is a disguised build of Nmap's own Ncat utility (88119be028596ae376318a37d8baa146d7b2f7a97ae3acac4a73db3abeaea866), carrying a fully valid signing chain from "Insecure.Com LLC; DigiCert EV Code Signing CA (SHA2); DigiCert" — the same certificate authority chain that legitimately signs Nmap's own releases — yet…
#Ncatmasquerading#DigiCertEVcertificateabuse#Zerologonexploit#Contiransomware#Petyaransomware#LockBitransomware#TeslaCrypt#anti-sandboxtechniquesActorsLockbit Gang · DragonForceIOCf9 · i0 · d0 · u0MITRE7
FILEMembersAug 16, 2026, 14:57 (UTC+9)WHQL-Signed Vulnerable Driver Hides in Unsigned Stealer Bundle
A twelve-file submission batch built around commodity stealers and loaders carries one outlier that changes its risk profile entirely: a 34-kilobyte driver called ProcessMonitorDriver, signed through a legitimate Microsoft Windows Hardware Compatibility Publisher chain, that trips Elastic Security's `Windows_VulnDriver_ProcessMonitorDriver` detection rule — the community's marker for a WHQL-blessed driver that is also abusable to kill security tooling.
#BYOVD#vulnerabledriver#Amadey#StealC#Lumma#ClipBanker#PowerLoader#crimewaredistributionIOCf12 · i2 · d0 · u3MITRE40RegionsAL · DE · ECIndustriesCommercial Services
FILEMembersAug 16, 2026, 06:51 (UTC+9)Three Domains, Three Registrars, One Identical 89-Day Cert Span
Three domains registered through three unrelated registrars — smileplz.com through Bluehost Inc., veonetwork.com through Cosmotown with Cloudflare nameservers, voxdream.com through Dynadot Inc. with Bunny.net nameservers — were each issued a Let's Encrypt certificate carrying an identical 89-day validity span, all inside a 33-day issuance window running from 2026-07-07 to 2026-08-09.
#Emotet#TA542#MummySpider#Let'sEncryptcertificateabuse#autodiscoverphishing#domaininfrastructureclustering#webmailimpersonation#macrodownloaderActorsEmotet Group · TA542IOCf4 · i0 · d3 · u6RegionsNGIndustriesManufacturing
FILEMembersAug 15, 2026, 14:31 (UTC+9)Fake Activation Tool Hides From Sandboxes, Not Scanners
A 744-kilobyte PowerShell script circulating under the name of a familiar piracy tool — MAS_AIO.cmd, the all-in-one installer bundled with the open-source Microsoft Activation Scripts project — carries a detection profile that should worry defenders more than its modest flagging count suggests. Fourteen of 76 engines call the file malicious and VirusTotal classifies it hacktool.presenoker/abapplication, yet the lone sandbox that ran it came back clean, zero malicious verdicts out of one.
#PowerShelldropper#MicrosoftActivationScriptslure#sandboxevasion#TA505#rockloader#wildcardcertificate#piracy-toolmalware#Let'sEncryptabuseActorsTA505 · Hive0065IOCf1 · i1 · d2 · u1MITRE16
FILEMembersAug 15, 2026, 07:01 (UTC+9)One Chinese Signing Identity Ties Together Sixteen 'Different' Malware Families
The most durable artifact in a fresh batch of sixteen file indicators tagged to TA428 (alias ThunderCats) isn't a backdoor at all — it's a code-signing certificate. Thirteen of the sixteen files carry an identical signer chain issued to 成都赤侠信息科技有限公司 and rooted in DigiCert Trusted Root G4 via DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, spanning binaries as small as 95 KB and as large as 55.9 MB. Detection ratios across that cohort run from 2 out of 76 engines to 32 out of 75.
#TA428#ThunderCats#code-signingcertificate#DigiCert#Chineseadwareoperator#malwarenamingtaxonomy#PUP#sandboxevasionActorsTA428 · ThunderCatsIOCf54 · i0 · d0 · u0MITRE22RegionsCA · CN · THIndustriesTelecommunications · Utilities
FILEMembersAug 13, 2026, 22:37 (UTC+9)Fake Anti-Cheat Installer Hides Beacon Behind China Unicom, CDN Certs
The most concrete artefact in this record is a single file: an installer named ACE-Setup.exe, signed end-to-end under a valid DigiCert-anchored chain running from ACEVILLE PTE LTD through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert Trusted Root G4. Its product string reads "Anti-Cheat Expert," and its embedded file paths reference two specific games — Delta Force and ABInfinite — placing the binary inside the exact directory structure…
#Confucius#beaconmalware#codesigningabuse#ChinaUnicom#CDNimpersonation#anti-cheatsoftware#gamingsector#TLScertificateabuseActorsConfuciusIOCf4 · i10 · d0 · u0
FILEMembersAug 12, 2026, 14:41 (UTC+9)15-Year-Old Sality Worm's TLS Fingerprint Ties to Tofsee C2
A Windows binary that first surfaced in mid-2010 is still being resubmitted for scanning as recently as October 2025, and its TLS behaviour trips a crowdsourced intrusion-detection rule built for an entirely different malware family. The sample is labelled trojan.sality/badcrypt and flagged by 57 of 76 engines, placing it squarely in the Sality file-infector lineage — an old, well-understood worm chassis.
#Sality#Tofsee#JA3fingerprint#clippermalware#USBpropagation#C2infrastructure#polymorphicpacker#commoditymalwareActorsSalty Spider · KuKuIOCf13 · i2 · d5 · u4MITRE32RegionsBD
FILEMembersAug 10, 2026, 06:52 (UTC+9)Mining-Themed Certificate Emerges as Prometei Files Go Quiet
The freshest artefact in this collection window is not a payload — it is a single IP address, 31.56.209.100, sitting on AS 209373 and carrying a Let's Encrypt certificate whose subject line reads corvusxmr.live. That domain, and its companion mine.corvusxmr.live and www.corvusxmr.live, describe themselves in the certificate's own subject-alternative-name field as Monero-mining infrastructure.
#OilRig#APT34#Prometeibotnet#Monerocryptomining#Let'sEncryptcertificate#telecommunicationssector#malwareattribution#command-and-controlinfrastructureActorsOilRig · APT34IOCf2 · i1 · d0 · u0MITRE8IndustriesTelecommunications
FILEMembersAug 9, 2026, 11:05 (UTC+9)One Certificate Signs Launcher, App, and Repair Tool in 3 Minutes
A single code-signing certificate — issued to SPRING (SG) PTE. LTD through the DigiCert Trusted G4 Code Signing chain — covers three functionally distinct Windows binaries: a launcher, an installed application, and a self-repair utility, all signed between 06:04 and 06:07 AM on August 2, 2026. That three-minute spread across three separate files is the most concrete fact in this record, and it reads less like three developers reaching for the same certificate and more like one build pipeline…
#codesigningcertificateabuse#DigiCert#Zenlayer#TLScertificatereuse#APT28misattribution#IcedID#maliciousfilehashes#governmentsectortargetingActorsAPT28 · StrontiumIOCf5 · i6 · d0 · u0MITRE38IndustriesGovernment
FILEMembersAug 9, 2026, 01:56 (UTC+9)Fake Root CA Signs Pirated KMS Activation Tools
Four Windows activation cracks distributed under the KMSpico and AutoKMS names carry an identical code-signing chain — but the authority that issued it isn't Sectigo, DigiCert, or any of the trust roots Windows ships with. It's "@ByELDI Certificate Authority," a self-manufactured root the operators built themselves, and every certificate under it fails Windows' own validation check.
#KMSpico#AutoKMS#codesigningabuse#self-signedcertificate#piratedsoftware#dynamicDNS#anti-analysistechniques#PatchworkActorsPatchwork · ChinastratsIOCf14 · i1 · d1 · u1MITRE51
FILEMembersAug 9, 2026, 00:27 (UTC+9)One Code-Signing Certificate Covers 14 WaveBrowser Bundleware Files
A single leaf certificate — serial 09 D7 7A 45 C1 C0 97 55 AE 3E 7A 51 53 98 3C 03, issued to "Wavesor Software (Eightpoint Technologies Ltd. SEZC)" under the DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 chain — signs all fourteen core binaries CTX Team has catalogued for a browser-and-updater bundle marketed as WaveBrowser and its companion SWUpdater service.
#codesigningcertificateabuse#bundleware#WaveBrowser#SWUpdater#PUA/adware#sandboxevasion#Authenticodetrust#misattributionActorsAPT28 · StrontiumIOCf16 · i1 · d0 · u0MITRE9IndustriesEducation & Research
FILEPublicAug 8, 2026, 23:59 (UTC+9)Signed Process Hacker Driver Now Anchors a Four-Stage Attack Chain
A signed kernel driver that Microsoft's own trust chain still vouches for is quietly doing double duty as a privilege-escalation primitive, and it is not travelling alone. The newest indicators added to a long-tracked Process Hacker 2 file set — both the x86 and x64 builds of kprocesshacker.sys (0f97f6d53fff…, 70211a3f9037…) — fire the LOLDrivers-catalogued rule PUA_VULN_Driver_Wj_Kprocesshacker_7021 despite carrying a fully valid DigiCert code-signing chain.
#ProcessHacker#BYOVD#kprocesshacker.sys#LOLDrivers#NirSoft#credentialtheft#signedmalware#kernelprivilegeescalationActorsRoyal Ransomware · Team OneIOCf35 · i0 · d0 · u0IndustriesGovernment
FILEPublicAug 8, 2026, 19:48 (UTC+9)One Trojan Sample Shows Full Evasion Playbook, No Campaign in Sight
A Win32 executable currently flagged by 61 of 76 antivirus engines packs a textbook sandbox-evasion triad — checking for an attached debugger, reading the CPU clock directly, and inspecting the CPU model string — into a single unsigned dropper that has circulated under at least four unrelated decoy filenames since 2016. What makes the sample newsworthy is not a hosting cluster or a signing certificate; there is neither.
#trojan.python/fkuk#stitchmalwarefamily#sandboxevasion#WMIdiscovery#HolyWater#StormCloud#persistencetechniques#lurefilenamesActorsHolyWater · Storm CloudIOCf1 · i0 · d0 · u0IndustriesEducation & Research
FILEMembersAug 5, 2026, 11:49 (UTC+9)Pirated Windows Activator Bundle Hides Shared Base64 Execution Trick
A "Microsoft Activation Scripts" archive built to bypass Windows and Office licensing is now doubling as a delivery mechanism for base64-encoded PowerShell payloads — and the same authoring fingerprint shows up in two structurally different file types inside the same drop. Eight of nine files tied to this indicator set carry file paths referencing "MAS/Separate-Files-Version" or "MAS/All-In-One-Version-KL," all first appearing within a 48-hour window between July 4 and July 6, 2026.
#TA505#rockloader#hacktool.autokms#hacktool.kmsauto#base64PowerShellexecution#KMSactivationpiracy#WindowsOfficelicensing#.winTLDDNScallbackActorsTA505 · Hive0065IOCf10 · i1 · d0 · u0MITRE13
FILEMembersAug 4, 2026, 13:47 (UTC+9)Validly Signed uTorrent Installer Hides Trojan.Offercore
An executable calling itself utorrent_installer.exe carries a fully valid four-tier code-signing chain — BitTorrent Inc, chained up through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 to DigiCert Trusted Root G4 — and yet 18 of 76 engines still flag it as trojan.offercore/r783575. That combination is the story here: not a forged certificate, but a genuine one riding on top of a payload the security industry has learned to distrust.
#trojan.offercore#code-signingabuse#uTorrent#anti-sandboxevasion#CloudFrontinfrastructure#P2Ptrafficmimicry#adware/PUP#TLScertificatespoofingIOCf28 · i4 · d2 · u0MITRE48RegionsAD · AE · AL · AMIndustriesChemicals · Commercial Services · Construction
FILEMembersAug 3, 2026, 21:49 (UTC+9)Vietnamese ISP Netblock, Not C2 Fleet, Behind Allaple Spread
Nineteen of the twenty IP addresses populated in this record sit inside a single netblock — 14.160.0.0/11, registered to VNPT Corp under AS45899 — and every one of them returns a VirusTotal detection ratio of either 0/91 or 1/91. That is not what a dedicated command-and-control fleet usually looks like. Purpose-built C2 infrastructure tends to concentrate on a handful of dedicated hosts with at least some flagged reputation, rented specifically for the operation and often swapped out once…
#Allapleworm#VNPTCorp#AS45899#Vietnam#masqueradingT1036#SynologyNAS#trojan.allaple#consumerISPaddressspaceIOCf33 · i23 · d0 · u0MITRE25RegionsUSIndustriesRetail
FILEMembersAug 2, 2026, 05:49 (UTC+9)Fake Shipping Documents Deliver AgentTesla Stealer Under Five Packers
The payload doesn't look like malware when it lands in an inbox. It looks like a vessel particulars sheet — "MV TBN SHIP PARTICULARS.docx.exe," "SHIP PARTICULARS - MV OSTC01.xlsx.exe," "MV PACIFIC ENDEAVOR V2202 PARTICULARS I.docx.exe." Each of those alternate filenames belongs to the same 490KB Windows executable, a double-extension trick that hides an EXE behind a familiar Word or Excel icon — a lure built for whoever in a shipping or freight-forwarding chain is used to receiving cargo…
#AgentTesla#spear-phishing#maritimeshippinglure#double-extensionmalware#.NETobfuscation#SMTPexfiltration#APT29misattribution#commodityinfostealerActorsAPT29 · MinidionisIOCf9 · i0 · d2 · u0MITRE38