CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • FILEMembersJun 26, 2026, 10:15 (UTC+9)

    A ZIP, a Batch Script, a Fake PDF Previewer: Inside a Staged Malware Chain

    A cluster of 24 file indicators submitted between June 1 and June 24, 2026 traces a delivery pattern that looks less like a single tailored intrusion and more like an assembly line: an archive carrying one batch script, a MSIL loader wearing the metadata of a document-preview utility, and a separate stealer sample whose YARA hits span everything from ransomware command detection to crypto-wallet browser extension harvesting.

    #AgentTesla#XWorm#commoditymalware#MSILloader#ZIParchivedelivery#browsercredentialtheft#sandboxevasion#builder-kitmalware
    IOCf24 · i1 · d0 · u1MITRE38RegionsBR · EG · ES · GBIndustriesAutomotive · Consulting · Education & Research
  • FILEMembersJun 26, 2026, 02:43 (UTC+9)

    EV Certificate Held 13 Months Before Signing Four Malicious Payloads

    Four Windows executables and an MSI installer, all bearing a valid Sectigo Extended Validation code-signing certificate issued to a company called "ORYON TECH LIMITED," began circulating through cracked-software distribution channels in April 2026 — but the certificate that makes them look legitimate to Windows SmartScreen and most endpoint defences was acquired more than a year before the first payload ever appeared.

    #ORYONTECHLIMITED#Microleaves#Legionadware#LummaStealer#EVcertificateabuse#pay-per-install#sandboxevasion#Romania
    IOCf20 · i1 · d5 · u13MITRE29RegionsSRIndustriesRetail · Telecommunications
  • FILEMembersJun 25, 2026, 22:43 (UTC+9)

    Single Obfuscation Builder Links BAT Stager and MSIL Dropper in 19-Country Campaign

    An 8-kilobyte DOS batch file and an 85-kilobyte .NET executable — separated by file type, detection rate, and apparent purpose — turn out to share a single obfuscation fingerprint that binds them into a deliberately engineered attack chain. The YARA rule SUSP_PS1_JAB_Pattern_Jun22_1, authored by Florian Roth of Nextron Systems and drawn from the Neo23x0 signature-base, co-fires on both components: the batch stager (SHA-256 02af6b5d…) and the MSIL dropper (SHA-256 d35dbfec…).

    #MSILdropper#BATstager#PowerShelldownloader#Bitviseimpersonation#content-typespoofing#sandboxevasion#technologysector#multi-countrycampaign
    IOCf9 · i0 · d1 · u2MITRE30RegionsAT · BD · CA · CHIndustriesAgriculture · Education & Research · Media
  • FILEMembersJun 25, 2026, 18:28 (UTC+9)

    Salty Spider Hides Expiro in Adobe's Own Sandbox Temp Path

    A 60-kilobyte GZIP archive, first submitted to VirusTotal on 22 March 2025, sits at the centre of an evasion architecture that has so far produced zero detections across 78 scanning engines. The file's distinguishing feature is not its contents — those remain opaque without a sandbox verdict — but where it lives: every observed submission path resolves to C:\Users\user\AppData\Local\Temp\acrocef_low\, the low-integrity process temp directory belonging to Adobe Acrobat's Chromium Embedded…

    #SaltySpider#Expiro#AdobeAcrobatCEFsandbox#CDNcertificatemasquerade#AkamaiTLSspoofing#DigiRomaniaASN8708#enterpriseendpointevasion#fileinfector
    ActorsSalty Spider · KuKuIOCf55 · i1 · d0 · u0MITRE29
  • FILEMembersJun 25, 2026, 14:18 (UTC+9)

    Gorgon Group Wraps Commodity Stealers in Four-Layer Evasion Stack

    A GZIP archive bearing the filename "RFQ Number QUO19009852.exe" is the outermost layer of a credential-theft operation that CTX Team has been tracking against Windows endpoints. The file is unremarkable at first glance — a compressed archive mimicking a supplier quotation request, the kind of attachment that moves through purchasing inboxes without triggering much suspicion.

    #GorgonGroup#ponystealer#predator_pain#PEiDpacking#spear-phishing#credentialtheft#anti-forensictimestamp#procurementlure
    ActorsGorgon Group · SubaatIOCf7 · i0 · d0 · u0MITRE41
  • FILEMembersJun 25, 2026, 10:07 (UTC+9)

    LummaStealer Campaign Hides Nine C2 Domains Behind One Server

    Nine command-and-control domains provisioned in a single week in December 2025 form the backbone of an active LummaStealer campaign targeting India — and the infrastructure's construction reveals an operator who planned for partial takedown from the outset. Eight of those domains share a single self-signed TLS certificate serial and, in seven cases, a single resolving IP address, meaning the elaborate domain pool amounts to DNS-level wallpaper over one physical server.

    #LummaStealer#AutoItdropper#C2infrastructure#India#credentialtheft#self-signedTLS#malware-as-a-service#infrastructurecompartmentalisation
    IOCf10 · i0 · d9 · u17MITRE31RegionsIN
  • FILEMembersJun 23, 2026, 22:05 (UTC+9)

    WZTeam KMS Trojan Stacks Five Evasion Layers Behind 23-Year Cert

    ##A 23-Year Certificate and Five Stacked Evasion Layers: Inside the WZTeam KMS Trojan Chain Three UPX-packed Windows executables presenting as KMSAuto++ activation tools have been circulating with a self-issued code-signing certificate that carries a validity window stretching to the year 2039 — a deliberate, long-lived signing identity engineered to pass casual inspection at the moment a user decides whether to run a crack.

    #WZTeam#KMSAuto#Koadic#PowerShelldownloader#code-signingabuse#Mexico#Philippines#defenseevasion
    ActorsAPT27 · TEMP.HippoIOCf9 · i1 · d0 · u2RegionsMX · PH
  • FILEMembersJun 23, 2026, 06:07 (UTC+9)

    Fake uTorrent Installers Pair Valid Code Signing With CDN Impersonation

    A cluster of Windows installers dressed up as the BitTorrent and uTorrent clients is circulating alongside a supporting network layer that borrows something rarely seen in commodity adware distribution: wildcard TLS certificates minted for someone else's brand. Three unrelated hosting providers — Digi Romania S.A. (AS8708, Romania), Advania Island ehf (AS50613, Iceland), and a Singapore-registered network called ACE (AS139341) — each present certificates whose subject lines point to major CDN…

    #BitTorrent#uTorrent#code-signingcertificate#CDNimpersonation#wildcardTLScertificate#CloudFront#adware#bundlewareinstaller
    IOCf28 · i4 · d2 · u0MITRE46RegionsBR · CA · CG · CHIndustriesEducation & Research · Technology · Telecommunications
  • FILEMembersJun 22, 2026, 18:33 (UTC+9)

    Revoked 2005 Certificate Still Delivering LSA Credential Stealer in 2026

    A Windows executable bearing a webHancer Corporation code-signing certificate — issued by ThawteCode Signing CA, valid only from August 2004 to September 2005, explicitly distrusted, time-invalid, and with revocation status listed as offline — was submitted to threat intelligence platforms as recently as March 6, 2026. That single observation frames everything that follows: a multi-component bundle combining two distinct mid-2000s adware product lines, a versioned auto-update delivery mechanism…

    #LSAcredentialdumper#adware-trojanhybrid#revokedcode-signingcertificate#NewDotNet#webHancer#CEDP.Stealer#telecommunicationssector#sandboxevasion
    IOCf16 · i2 · d2 · u4MITRE43RegionsGB · MXIndustriesTelecommunications
  • FILEMembersJun 22, 2026, 18:17 (UTC+9)

    Meteorite Downloader Delivers Azorult and OskiStealer to Media Targets

    A Varist-packed dropper self-identifying as "Meteorite Downloader v3.01" has been observed targeting media organisations in Canada, France, and the United States, delivering Azorult and OskiStealer credential-theft payloads through a layered evasion stack that combines timing-based sandbox defeat, three concurrent process-injection sub-techniques, and active suppression of security tooling.

    #MeteoriteDownloader#Azorult#OskiStealer#Varistpacker#mediasector#processinjection#credentialtheft#multi-clusterinfrastructure
    IOCf3 · i0 · d11 · u3MITRE21RegionsCA · FR · USIndustriesMedia
  • FILEMembersJun 21, 2026, 21:17 (UTC+9)

    Godzilla Loader Campaign Byte-Mutates Five Variants, Exfiltrates India Victim's Documents

    Five nearly identical 9-kilobyte Windows executables are circulating as the primary delivery mechanism for a Godzilla Loader campaign whose most operationally revealing detail is not the malware itself — it is the five zero-detection text files sitting in the same dataset, each one a harvested document from a victim's own machine, packaged with a unique victim token and dual collection timestamps from July and August 2024.

    #GodzillaLoader#FileGrabber#India#dataexfiltration#bytemutation#C2infrastructure#PE32loader#stealer
    IOCf12 · i0 · d5 · u6MITRE30RegionsIN
  • FILEMembersJun 21, 2026, 17:14 (UTC+9)

    EV-Signed Video Downloader Hides MSSQL Backdoor, Hits Zero AV Detections

    Five Windows executables distributed under two consumer software brands — PPTube and iTubeGo YouTube Downloader Pro — arrived on VirusTotal between June 3 and June 6, 2026, each bearing a validly verified Sectigo Extended Validation code-signing certificate issued to an entity called "ByteHub Technology Inc." Every antivirus engine on the platform returned a clean verdict.

    #Skip-2.0#MSSQLbackdoor#EVcode-signingabuse#PyArmor#telecommunicationssector#GermanySwedenThailand#ByteHubTechnologyInc#piracy-channeldelivery
    IOCf28 · i1 · d2 · u1MITRE8RegionsDE · SE · THIndustriesTelecommunications
  • FILEMembersJun 20, 2026, 16:47 (UTC+9)

    APT28 Cracked-Software Lure Rode 16-Month-Old C2 Infrastructure

    A single Windows executable masquerading as five popular pirated applications reached 37 independent submission sources within twelve days of its first appearance — not because the operator rushed the deployment, but because the infrastructure waiting to receive it had been quietly assembled more than a year in advance. The C2 certificate was minted in January 2025. The domains were batch-registered in April 2026. The payload surfaced in June 2026.

    #APT28#Trojan.Remus/Wingo#crackedsoftwarelure#stealertrojan#C2infrastructure#sandboxevasion#credentialharvesting#Ukrainehosting
    ActorsAPT28 · StrontiumIOCf1 · i1 · d2 · u2MITRE11RegionsBD · BR · CA · CLIndustriesFood & Beverages
  • FILEMembersJun 20, 2026, 16:33 (UTC+9)

    LHA Lure Drops PureLog Stealer and XWorm With 0/76 Persistence Layer

    A 935-kilobyte ZIP archive named docPO-Q-2606010-ASN _ ZBSPR26-007.PDF(849KB).LHA is circulating as a spearphishing attachment across engineering firms, retail organisations, and telecommunications providers in Bosnia-Herzegovina, Colombia, the Czech Republic, Malaysia, and the United States. The filename is a layered deception: the .LHA extension appended after a fake PDF size annotation is engineered to make the archive read as a harmless purchase-order document to a distracted procurement or…

    #PureLogStealer#XWorm#spearphishingattachment#double-extensionlure#.NETReactor#DDNScommand-and-control#engineeringandtelecomsectors#SetupComplete.cmdpersistence
    IOCf23 · i3 · d1 · u2MITRE60RegionsBA · CO · CZ · MYIndustriesEngineering · Retail · Telecommunications
  • FILEMembersJun 19, 2026, 09:13 (UTC+9)

    Stealc v2 Adds Chrome Encryption Bypass in Two-Stage Stealer Pivot

    Twelve new files and a single Spamhaus DROP-listed IP are the visible footprint of a credential-theft operation that has materially retooled since its earlier iteration. Where prior coverage documented a SmokeLoader-based lure with multiple C2 nodes, the campaign now deploys a sequenced SVCStealer loader and Stealc v2 payload — two unsigned 64-bit Windows executables that independently check in to the same raw IPv4 address, 62.60.226.159, hosted under AS214351 (Femo IT Solutions Limited,…

    #Stealcv2#SVCStealer#infostealer#Chromeapp-boundencryptionbypass#Exoduswallet#Romania#bullet-proofhosting#two-stageloader
    ActorsAPT28 · StrontiumIOCf31 · i1 · d0 · u1MITRE42RegionsAU
  • FILEMembersJun 19, 2026, 08:48 (UTC+9)

    Gozi Banking Trojan Routes C2 Through Trio of Tor Onion Addresses

    Three algorithmically generated Tor v3 hidden-service addresses — each a 56-character base32 string indistinguishable from random noise — are currently routing bot check-ins for an active Gozi banking-trojan campaign tracked by CTX Team as CTXv7povuldk2. The addresses were not registered through any conventional registrar, carry no TLS certificates that could be fingerprinted, and leave no DNS footprint that a sinkhole could intercept.

    #Gozi#ISFB#Torhiddenservices#DGA#bankingtrojan#C2infrastructure#compile-after-delivery#datadestruction
    IOCf24 · i0 · d3 · u1MITRE38
  • FILEMembersJun 19, 2026, 05:02 (UTC+9)

    Signed Adware Dropper Hits 39 Countries With 2/76 AV Detections

    A trojanised BitComet installer bearing a commercially obtained Sectigo code-signing certificate is circulating across 39 countries, achieving a detection rate of just 2 out of 76 engines on its dropper component — not through novel exploitation or zero-day tradecraft, but through the deliberate layering of a valid certificate chain, sandbox-evasion instrumentation, and AWS CloudFront CDN abuse into what is, on the surface, a routine adware distribution campaign.

    #DealPly#Offercore#code-signingabuse#sandboxevasion#adware#Chromeextensionpersistence#CDNabuse#educationsector
    IOCf59 · i4 · d1 · u0MITRE48RegionsAL · BG · BR · BSIndustriesEducation & Research · Financial Services · Technology
  • FILEPublicJun 19, 2026, 00:42 (UTC+9)

    YoroTrooper's AveMaria RAT Dropper Stacks Five Evasion Layers Before C2 Contact

    Since CTX Team's earlier coverage of a WarzoneRAT cluster targeting Turkish organisations, two new file indicators have surfaced alongside the same Microsoft-themed infrastructure backbone — and the tradecraft picture they reveal is considerably more elaborate than a routine IOC refresh. The primary dropper, a 668-kilobyte Win32 PE32 executable catalogued under SHA-256 69415b18aeb7e75f4843313ed5c65e09b1a2a41d73af0ce7fed40e0f2cc2b0a0, stacks five discrete anti-analysis mechanisms before it ever…

    #YoroTrooper#AveMariaRAT#WarzoneRAT#UACbypass#processinjection#sandboxevasion#CentralAsia#typosquatinfrastructure
    ActorsYoroTrooperIOCf2 · i0 · d2 · u0MITRE21
  • FILEPublicJun 19, 2026, 00:24 (UTC+9)

    10KB SystemBC Dropper Evades Both Sandboxes in Saudi Telecom Attack

    ##A 10-Kilobyte Ghost: How a Zero-Import SystemBC Dropper Defeated Every Sandbox Targeting Saudi Telecom A single 10-kilobyte unsigned Windows executable — compact enough to fit inside a typical email attachment header — has been identified in a campaign against telecommunications infrastructure in Saudi Arabia, carrying a technical profile that exposes a deliberate gap in how most enterprise detection pipelines are built.

    #DragonForce#SystemBC#Coroxy#sandboxevasion#telecommunications#SaudiArabia#bullet-proofhosting#proxy-RAT
    ActorsDragonForce · DragonForce MalaysiaIOCf1 · i1 · d0 · u0MITRE8RegionsSAIndustriesTelecommunications
  • FILEPublicJun 18, 2026, 20:29 (UTC+9)

    AgentTesla Stealer Activates Three-Year-Old Tanzanian Domain in Single Day

    On the morning of 2 June 2026, two events occurred in close enough succession to rule out coincidence. At 12:23:47 UTC, a 90-day wildcard TLS certificate was issued by Let's Encrypt — issuer CN=YR1, serial 5fe3baf35c3534571f8e352115b86a4e57b — covering every possible subdomain of hhautoinvestment.co.tz, a Tanzanian-registered domain that had sat dormant since its registration on 24 August 2023.

    #AgentTesla#credentialharvesting#processhollowing#FTPexfiltration#ageddomaininfrastructure#manufacturing#healthcare#TanzaniaccTLD
    IOCf3 · i0 · d1 · u1MITRE47RegionsAE · DE · DK · JPIndustriesArts & Entertainment · Automotive · Business Associations
  • FILEMembersJun 17, 2026, 11:08 (UTC+9)

    Dormant Snapchat Lure Domain Wakes After 13 Months to Serve LummaStealer

    A domain registered in April 2025 under the guise of a Snapchat mod APK resource sat completely inactive for thirteen months before its operator flipped a switch in May 2026: a Let's Encrypt TLS certificate was issued, six numbered Windows executables appeared at predictable paths, and a social-engineering notes file went live alongside them.

    #LummaStealer#VenomRAT#QuasarRAT#credentialtheft#cryptocurrencywalletharvesting#Canada#Telegramexfiltration#domainaging
    IOCf9 · i0 · d1 · u8MITRE41RegionsCA
  • FILEMembersJun 17, 2026, 10:36 (UTC+9)

    GuLoader Hits EU Healthcare via Danish Temp Folder and Forged 2013 Timestamp

    A 673-kilobyte Windows executable with a Polish-language filename — Zamowienie_829522.bat, meaning "Order 829522" — is the entry point for one of the more technically deliberate GuLoader campaigns CTX Team has tracked against European healthcare targets. The file is a Nullsoft Installer self-extracting archive, flagged by 49 of 77 antivirus engines under the label trojan.makoob/nsis, and it arrives carrying a PE timestamp set to Christmas Day 2013 — a date approximately eleven years before the…

    #GuLoader#NSISdropper#healthcaresector#Poland#Croatia#JPEGsteganography#cPanelC2infrastructure#ransomwareprecursor
    IOCf16 · i1 · d2 · u2MITRE19RegionsHR · PLIndustriesHealthcare
  • FILEMembersJun 15, 2026, 11:35 (UTC+9)

    WinosStager Loader Hides Behind Chrome, Routes All C2 Through Tor

    A 66,879-kilobyte Windows executable dressed as Google Chrome is circulating across chemicals, consulting, government, and manufacturing organisations in ten countries — and every byte of its command-and-control traffic flows exclusively through the Tor anonymity network to algorithmically generated .onion hidden services, leaving no clearnet address for network defenders to block, sinkhole, or pivot from.

    #WinosStager#CleverSoar#TorC2#Chromeimpersonation#compile-on-host#manufacturing#government#Skip-2.0
    IOCf23 · i0 · d2 · u0MITRE51RegionsGU · IN · IT · MYIndustriesChemicals · Consulting · Government
  • FILEPublicJun 15, 2026, 11:19 (UTC+9)

    APT1 Freeware Lure Still Active 12 Years On, Live Cert Reveals

    A 527-kilobyte Windows executable presents itself to the world as a routine archiving utility. Its internal product string reads "B1 Free Archiver Installer," its filename circulates as B1FreeArchiver_1.4.68.exe, and its copyright notice is dated 2013. None of that is what it is. Forty-three of 77 antivirus engines classify the binary as adware.catalina/downware — a trojanised installer that bundles unwanted payloads under a recognisable freeware brand — and three concurrent IDS rules confirm…

    #CommentCrew#APT1#adware.catalina#freewaremasquerading#content-typespoofing#educationsector#SouthAsia#glassesmalwarefamily
    ActorsComment Crew · Byzantine CandorIOCf4 · i1 · d0 · u0MITRE25RegionsSAIndustriesEducation & Research
  • FILEPublicJun 14, 2026, 19:07 (UTC+9)

    Trojanized Black Myth: Wukong Launcher Delivers Rancor Trojan to Thai Users

    A 457-kilobyte Windows executable named "Launcher Black Myth Wukong.exe" is circulating in Thailand, masquerading as the Steam launcher for one of 2024's most widely played game titles — and carrying a Rancor-family trojan payload that 52 of 76 antivirus engines now flag as malicious while the Zenbox sandbox returns a clean verdict at 98% confidence. The gap between those two numbers is the story: the operators behind this campaign did not rely on a single evasion trick.

    #Snowglobe#AnimalFarm#Rancor#Babar#Thailand#gaminglure#sandboxevasion#espionage
    ActorsSnowglobe · Animal FarmIOCf3 · i0 · d1 · u0MITRE21RegionsTH
  • FILEPublicJun 14, 2026, 14:58 (UTC+9)

    Dual-Certificate PCHunter Stack Hits Finance and Telecom Across 14 Nations

    A VMProtect-packed, DigiCert EV-signed executable and a Microsoft WHQL-cross-signed kernel driver — both components of the PCHunter Windows inspection utility, both carrying certificates that expired years ago but were valid at the moment of signing — are circulating in active operations against financial services, technology, and telecommunications organisations across fourteen countries.

    #PCHunter#RoyalRansomware#WHQLdriverabuse#VMProtect#kernel-modedriver#financialservices#code-signingevasion#espionage
    ActorsRoyal Ransomware · Team OneIOCf3 · i0 · d0 · u0MITRE25RegionsAT · CA · CL · CNIndustriesFinancial Services · Technology · Telecommunications
  • FILEMembersJun 14, 2026, 03:28 (UTC+9)

    Thailand Telco Trojan Hides Banking Payload Inside Fake IDM Crack

    Somewhere between a piracy forum and a Thai telecom workstation, a 59-kilobyte executable named IDM_6.4x_Crack_v19.7.exe is doing something its would-be users never expected: running a layered evasion gauntlet that defeats at least one automated sandbox entirely before handing off to a 12-megabyte dropper that quietly installs a banking-capable payload, establishes registry persistence, and then erases itself from disk.

    #xegumumune#bankingtrojan#Thailand#telecommunications#sandboxevasion#WMIexecution#piracylure#C2infrastructure
    IOCf20 · i1 · d1 · u0MITRE47RegionsTHIndustriesTelecommunications
  • FILEMembersJun 13, 2026, 06:59 (UTC+9)

    17-Year-Old Kernel Driver Powers 2026 Credential-Theft Campaign Across 7 Countries

    Since CTX Team's earlier coverage of a trojanized CorelDraw crack campaign targeting Brazil, two new file samples have surfaced that confirm the operator is not winding down — they are building out. The most recent addition carries a PE compilation timestamp of 2026-05-08 and was first submitted to VirusTotal just three days later, on May 11.

    #InjectorNett#PureLogs#WinRing0x64BYOVD#LOLDrivers#cryptomining#credentialtheft#AS213010#NICENICinfrastructure
    IOCf7 · i2 · d3 · u4MITRE58RegionsAU · BD · BR · ESIndustriesConstruction · Hospitality & Leisure · Manufacturing
  • FILEMembersJun 12, 2026, 22:44 (UTC+9)

    Sefnit C2 URI Unchanged for a Decade as Campaign Hits Thai Telecoms

    A single line of HTTP traffic — gettasks.php?protocol=0&protoversion=201&o=0&p=C:%5CUsers%5Cadmin%5CAppData%5CLocal%5CTemp%5Cexplorer.exe&f=7296000 — appears identically across four command-and-control domains whose registration dates span more than a decade, from a domain created in July 2013 through to one registered in January 2024.

    #Sefnit#Graftor#CeeInject#telecommunicationsservices#Thailand#processmasquerading#registrardiversification#command-and-controlinfrastructure
    IOCf3 · i1 · d4 · u12MITRE26RegionsTHIndustriesTelecommunications
  • FILEMembersJun 12, 2026, 07:28 (UTC+9)

    'mixseven' Affiliate Deploys Six Malware Families via Single PPI Tag

    A single pay-per-install affiliate operating under the publisher tag pub=mixseven has coordinated the simultaneous deployment of at least six distinct malware families — GCleaner, SmokeLoader, PrivateLoader, Socelars, Fabookie, RedLine Stealer, FFDroider, and Glupteba — through a layered loader chain whose network infrastructure was provisioned in a single automated session in September 2021.

    #mixseven#pay-per-install#GCleaner#SmokeLoader#RedLineStealer#Glupteba#credentialharvesting#PPIaffiliatenetwork
    ActorsSmoky Spider · BariumIOCf20 · i5 · d2 · u13MITRE64
  • FILEMembersJun 12, 2026, 03:25 (UTC+9)

    Trojanized CorelDraw Crack Hits Brazil With Four-Payload Attack Chain

    A trojanized CorelDraw activation archive that has reached 887 unique submitters since March 2025 is deploying a layered attack chain against Brazil's construction, hospitality, media, and retail sectors — one that combines a PureLogs credential stealer, an embedded coin-miner, a three-stage hosts-file poisoning sequence, and a Bring Your Own Vulnerable Driver (BYOVD) component borrowed from a 2008-era kernel driver.

    #PureLogs#BYOVD#WinRing0x64.sys#coin-miner#Brazil#piratedsoftwaredistribution#credentialtheft#AS213010
    IOCf17 · i2 · d3 · u4MITRE72RegionsBRIndustriesConstruction · Hospitality & Leisure · Media
  • FILEPublicJun 11, 2026, 23:43 (UTC+9)

    WarzoneRAT Invoice Lure Layers Anti-Analysis Stack Against Turkish Targets

    A 2,695-kilobyte Windows executable, packaged under the filename Invoice.exe and built inside a commercial crypter environment, carries one of the more deliberately constructed anti-analysis stacks CTX Team has documented in a commodity remote-access trojan deployment: timing-based sandbox evasion, debugger detection, reflective code loading, process injection, UAC bypass, and an aggressive indicator-removal suite — all wrapped in a TLS-encrypted C2 channel that hides behind a hostname…

    #GoldEvergreen#WarzoneRAT#AveMaria#Turkey#sandboxevasion#UACbypass#invoicephishing#C2infrastructure
    ActorsGold Evergreen · Business ClubIOCf1 · i0 · d2 · u0MITRE21RegionsTR
  • FILEMembersJun 11, 2026, 19:41 (UTC+9)

    OceanLotus Hid Denis Backdoor Behind Forged Microsoft Identity and DNS Tunnel

    Two Win32 executables compiled on the same December afternoon in 2015 represent something more instructive than their age might suggest: a precisely engineered deception stack in which every layer — binary identity, code-signing posture, execution behaviour, and network communications — was designed to pass as something legitimate. Both are Denis backdoor variants attributed to OceanLotus (also tracked as APT32, Canvas Cyclone, and Bismuth).

    #OceanLotus#APT32#Denisbackdoor#DNStunnelling#code-signingforgery#sandboxevasion#binarymasquerading#SoutheastAsiaespionage
    ActorsOceanLotus · APT32IOCf2 · i0 · d2 · u0MITRE12RegionsCN
  • FILEMembersJun 11, 2026, 16:10 (UTC+9)

    2345Pinyin IME Runs Six-Year Covert Delivery Pipeline Behind Ad-Injection Cover

    A Chinese-language input method editor has been quietly running a multi-tier asset-delivery pipeline on victim hosts since at least 2018 — one whose technical fingerprints look considerably more sophisticated than the advertisement injection it ostensibly exists to perform. The 2345Pinyin IME client, distributed by Shanghai 2345 Network Technology Co., Ltd.

    #2345NetworkTechnology#2345Pinyin#adware#PUA#HongKong#mediasector#CDNabuse#indicatorremoval
    IOCf44 · i5 · d0 · u0MITRE24RegionsHKIndustriesMedia
  • FILEMembersJun 11, 2026, 06:43 (UTC+9)

    XRed RAT Hits Peru Gov With Frozen 2019 Builder, AnyDesk Lures

    Three Windows executables masquerading as a Synaptics touchpad driver and AnyDesk remote-desktop installer are circulating against Peruvian government targets, carrying an XRed RAT payload whose compiled import table has not changed since at least June 2019. The same imphash — 332f7ce65ead0adfb3d35147033aabe9 — locks together samples whose first VirusTotal submissions span four years, from June 2019 through October 2023, and the campaign was still active as recently as May 2026.

    #XRedRAT#DarkKomet#Peruviangovernment#FreeDNSC2#sandboxevasion#espionage#commodityRAT#LatinAmerica
    ActorsCactus · Cactus Ransomware GroupIOCf14 · i1 · d0 · u0MITRE20RegionsPEIndustriesGovernment
  • FILEPublicJun 11, 2026, 02:57 (UTC+9)

    Trojanised KMSAuto Delivers SmokeLoader via Three-Layer Evasion Stack

    A trojanised Windows activation tool distributed through a software-piracy hosting path has been confirmed as the delivery vehicle for SmokeLoader, with the full infection chain relying on a deliberately engineered evasion stack — AutoIT compilation, aPLib decompression, UPX runtime packing, and active sandbox-fingerprinting — that goes well beyond what commodity pirated-software distributors typically invest in concealment.

    #SmokySpider#SmokeLoader#AutoIT#aPLib#UPXpacking#sandboxevasion#Mongolia#softwarepiracylure
    ActorsSmoky SpiderIOCf3 · i0 · d0 · u0MITRE28RegionsMN
  • FILEMembersJun 11, 2026, 02:44 (UTC+9)

    Autodesk Licensing Agent Hijacked to Drop Coinminer via DLL Sideload

    A trojanized crack package impersonating Autodesk's Network License Manager is exploiting the legitimate AdskLicensingAgent service to load attacker-controlled code — a DLL sideload [T1574.002] that turns a trusted enterprise software component into an unwitting execution vehicle. The lure is polished enough to have drawn 461 submissions from 417 unique sources since late March 2026, and the campaign's evasion layer is effective enough that one major automated sandbox rated the primary payload…

    #DLLsideloading#coinminer#AutodeskNetworkLicenseManager#AS213010#Brazilcontainersandpackaging#T1574.002#sandboxevasion#ParentLock.exe
    IOCf13 · i2 · d2 · u0MITRE53RegionsBRIndustriesContainers & Packaging
  • FILEMembersJun 10, 2026, 23:07 (UTC+9)

    Validly Signed uTorrent Installer Hides Trojanized Adware Payload

    A Windows installer carrying a fully valid BitTorrent Inc / DigiCert code-signing chain is circulating as a trojanized uTorrent Classic setup — flagged malicious by 22 of 76 antivirus engines even though every certificate check in the chain returns clean. The same build lineage produced an unsigned, PEiD-packed sibling that only 4 of 75 engines catch.

    #uTorrentimpersonation#code-signingabuse#TLScertificatespoofing#adware#offercore#inoci#myqcloud.comCDNimpersonation#PUAdistribution
    IOCf26 · i6 · d2 · u0RegionsAE · AL · AR · ATIndustriesCommercial Services · Education & Research · Hospitality & Leisure
  • FILEMembersJun 10, 2026, 07:34 (UTC+9)

    Allaple Worm Hijacks 20 German Business Servers as Silent C2 Relays

    Twenty static IP addresses, all assigned to small German businesses on Deutsche Telekom AG's T-DSL Business service, all falling within the same RIPE-registered netblock — 217.86.128.0 through 217.86.255.255, designated DTAG-STATIC02 — form the operational backbone of an Allaple worm campaign that CTX Team has tracked from February through June 2026. None of the twenty endpoints carry a single malicious detection across 91 scanning engines on VirusTotal.

    #Allaple#DeutscheTelekomAS3320#compromisedSMBinfrastructure#C2relaynetwork#sandboxevasion#wormpropagation#Germanbusinessservers#retailsectortargeting
    IOCf41 · i29 · d0 · u0MITRE25RegionsUSIndustriesRetail
  • FILEMembersJun 9, 2026, 20:32 (UTC+9)

    TA505 Dropper Sleeps Past Sandboxes, Stages Rockloader in 24 Countries

    A roughly one-megabyte JavaScript file — encoded in UTF-16 little-endian, packed by Varist, and bearing filenames that mimic business invoice PDFs — is circulating across engineering, healthcare, manufacturing, legal, technology, and telecom organisations in 24 countries, functioning as the first stage of a delivery chain that culminates in the download of a Windows executable attributed to the rockloader family.

    #TA505#rockloader#JavaScriptdropper#sandboxevasion#spear-phishing#invoicelure#everycarebd.com#espionage
    ActorsTA505 · Hive0065IOCf38 · i0 · d1 · u3RegionsAE · AT · AZ · BDIndustriesEngineering · Healthcare · Manufacturing
  • FILEMembersJun 9, 2026, 16:21 (UTC+9)

    Old Baixaki Typosquat Cluster Resurfaces via Unrelated 2026 CDN Certificate

    Three subdomains built around the name of Brazil's largest freeware portal, all registered on the same day in October 2012 through PDR Ltd. d/b/a PublicDomainRegistry.com, have re-entered current threat telemetry paired with an unrelated certificate observation on a commercial Brazilian CDN more than a decade later — a pairing that illustrates how stale infrastructure and fresh re-observation timestamps can be mistaken for a live campaign if analysts don't check the dates.

    #dealply#Baixakityposquat#AzionTechnologies#GlobalSigncertificate#adware/PUPdistribution#Brazil#staleIOC#VirtualDJinstallerlure
    IOCf7 · i2 · d3 · u1MITRE33RegionsBRIndustriesConsulting
  • FILEMembersJun 9, 2026, 08:22 (UTC+9)

    Fake 'Sanwhole' Cert Anchors Layered Crypto-Wallet Heist via Trojanised IDE

    A trojanised installer impersonating the developer tool "Netpas DevStudio" has been circulating with a self-fabricated code-signing certificate — issued by and to a fictitious entity called "Sanwhole" — whose chain terminates in an untrusted root that no legitimate certificate authority ever vouched for. Three files in the bundle carry the same fraudulent signature, the same certificate serial (26 F4 9B CA 07 79 1C 96 48 EA 3D 5A EA 7F 69 37), and the same thumbprint…

    #Cryptbot#EmotetGroup#code-signingabuse#cryptocurrencywallettheft#developertoollure#sandboxevasion#infostealer#DLLspoofing
    ActorsEmotet Group · TA542IOCf30 · i0 · d1 · u2MITRE39RegionsCI
  • FILEPublicJun 9, 2026, 04:10 (UTC+9)

    Football Manager 26 Crack Hides Two-Year-Old AutoIT Kill Chain

    Since CTX Team's earlier coverage of this campaign, nine additional file indicators have surfaced, deepening the tooling picture around a multi-stage infection chain that pairs trojanized game installers with a layered evasion stack that has remained structurally intact across at least two years of active operation. The newest sample — a 20.6 MB executable named fm.exe carrying Unity Technologies copyright metadata and the embedded path C:\Games\Football Manager 26\fm.exe — represents the…

    #Patchwork#APT-C-09#AutoIT#XMRig#BYOVD#WinRing0#cryptomining#LOLDrivers
    ActorsPatchwork · ChinastratsIOCf18 · i0 · d0 · u0MITRE45
  • FILEMembersJun 9, 2026, 00:37 (UTC+9)

    Salty Spider Pairs 7-Year Loader With Fresh Phorpiex Worm to Hit Transport

    ##A Seven-Year Loader Meets a Zero-Day Worm: Salty Spider's Layered Evasion Campaign Targets Transportation A freshly compiled Phorpiex worm variant — PE timestamp matching its first submission date of 2026-02-09, zero prior detection history at the moment of deployment — is circulating alongside a seven-year-old MSIL/AgentB trojan that successfully convinces automated sandbox analysis it is harmless, even as 48 of 76 antivirus engines flag it as malicious. The pairing is not accidental.

    #SaltySpider#Phorpiex#MSIL/AgentB#transportationsector#sandboxevasion#bulletproofhosting#USBsocialengineering#botnetC2
    ActorsSalty Spider · KuKuIOCf2 · i1 · d0 · u1MITRE25IndustriesTransportation
  • FILEMembersJun 9, 2026, 00:21 (UTC+9)

    Trojanized UltraSurf Proxy Rides Expired Cert Into 2026

    A Win32 build of the UltraSurf/Ultrareach censorship-circumvention proxy — a tool millions have used to punch through national firewalls — is still circulating years after the code-signing certificate underpinning it expired. The leaf certificate, issued to "Ultrareach Internet Corp." and valid from June 9, 2021 to June 9, 2024, is now flagged by validators as "not time valid," yet the GlobalSign intermediate and root certificates above it in the chain remain valid through 2029 and 2030.

    #UltraSurf#Ultrareach#Glupteba2#codesigningabuse#HurricaneElectricAS6939#self-signedcertificates#MuddyWater#SilentChollima
    ActorsMuddyWater · TEMP.ZagrosIOCf1 · i5 · d0 · u0MITRE18IndustriesEnergy
  • FILEMembersJun 8, 2026, 19:41 (UTC+9)

    PayPal Lure Fronts Three-Family Malware Stack Tied to FortiGate C2

    A trojanised credential-checker masquerading as a PayPal email validation tool has been serving as the entry point for a multi-stage payload operation that deploys at least three functionally distinct malware families — all wrapped in the same ConfuserEx Mod obfuscation layer — before routing command-and-control traffic to a single Russian IP address that presents a FortiGate appliance certificate.

    #Amadey#Mofksys#ConfuserEx#reflectiveloader#credentialtheft#Russia#paymentplatforms#worm
    IOCf12 · i1 · d0 · u3MITRE36RegionsRO
  • FILEMembersJun 8, 2026, 15:58 (UTC+9)

    Decade-Old Bundler Trojan Drops Tor-Routed MinerGate on Chemicals Workstations

    A 919-kilobyte UPX-compressed Windows executable masquerading as a routine software installer is functioning as the first stage of a two-component cryptomining chain that has been circulating since at least late 2016 and remains actively observed as of mid-2026. The dropper — internally branded "Carambis Installer" and carrying a ROSTPAY LTD.

    #PinchySpider#MinerGate#Carambisbundler#cryptomining#chemicalssector#TorC2#Proton66OOO#UPXpacking
    ActorsPinchy Spider · SodinokibiIOCf3 · i6 · d0 · u0IndustriesChemicals
  • FILEPublicJun 6, 2026, 16:11 (UTC+9)

    Trojanised KMS Activators Carry Konni Espionage Implant, WinDivert Sniffer

    Five trojanised Windows activation tools — distributed under the names KMSpico, KMSAuto, and AAct — carry an embedded user-mode packet-capture driver that has no legitimate place in any licensing utility. The YARA rule WinDivert_Driver fires on all five samples, and on one of them, AAct_x64.exe (sha256: db3aa782e297b2b5d9e2a1281ebb9afd416c82722c2d2a285ef94070e4cdd5d2), a second rule fires alongside it: win_konni_auto, a Malpedia-sourced signature that detects the Konni espionage implant family.

    #GamaredonGroup#Konni#WinDivert#KMSpico#piracylure#defencesector#code-signingabuse#espionage
    ActorsGamaredon Group · CTIGIOCf7 · i0 · d0 · u0MITRE6IndustriesDefense
  • FILEPublicJun 6, 2026, 16:00 (UTC+9)

    Trojanized Macro Tool Drops BroPass and RedlineStealer on Chilean Targets

    A 32-kilobyte Windows executable masquerading as a macro encryption utility has become the delivery vehicle for one of the more technically deliberate credential-theft operations CTX Team has tracked against Chilean targets in recent memory. The outer wrapper — an NSIS installer named macro_encrypter.exe — drops at least two distinct stealer families onto victim machines while simultaneously executing a layered evasion stack that includes active sandbox detection, base64-encoded gzip payloads,…

    #OperationSpalax#BroPass#RedlineStealer#NSISdropper#credentialtheft#Chile#sandboxevasion#code-signingabuse
    ActorsOperation SpalaxIOCf3 · i0 · d0 · u1MITRE30RegionsCL
  • FILEMembersJun 6, 2026, 07:45 (UTC+9)

    72-Hour Microsoft Cert Turns Warp Terminal Installer Into Signed Dropper

    On the morning of June 5, 2026, a trojanised installer impersonating the Warp Terminal application appeared on VirusTotal carrying a code-signing certificate that had been minted fewer than 48 hours earlier. The leaf cert — serial 33 00 01 A1 1D A4 AE AD B1 B2 1A 0F 7C 00 00 00 01 A1 1D, issued by Microsoft ID Verified CS EOC CA 04 under the subscriber identity "Denver Technologies, Inc. dba Warp" — was valid for exactly 72 hours, from June 3 to June 6, 2026.

    #ephemeralcodesigning#MicrosoftTrustedSigning#ProcessHacker2#trojanisedinstaller#signedbinaryabuse#TorC2#commercialservices#supplychaindelivery
    ActorsRoyal Ransomware · Team OneIOCf8 · i0 · d0 · u0MITRE6IndustriesCommercial Services
2
Of3
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.