FILEPublicJun 2, 2026, 12:47 (UTC+9)Signed Netease Emulator Files Hide MSSQL Backdoor, Fool All 76 AV Engines
Two trojanized components of Netease's MuMuPlayer Android emulator — both carrying a currently valid DigiCert code-signing certificate issued to Netease Interactive Entertainment Pte. Ltd. — have been identified embedding Skip-2.0 MSSQL authentication-bypass hooks inside legitimately signed Windows executables, achieving complete evasion across all 76 antivirus engines while routing command-and-control traffic through infrastructure that impersonates Akamai CDN.
#SpringDragon#Skip-2.0#MuMuPlayer#code-signingabuse#MSSQLbackdoor#educationandresearchsector#Akamaiimpersonation#supplychaincompromiseActorsSpring Dragon · Lotus BlossomIOCf2 · i3 · d1 · u0IndustriesEducation & Research
FILEMembersJun 2, 2026, 02:27 (UTC+9)Kimsuky Hides Guloader Behind Fake 'Brittlewort' Code-Signing Identity
A 326-kilobyte Windows executable named Zamówienie_Nr.2605011793800182.exe — Polish for "Order No." with a plausible invoice string appended — arrived in analysis pipelines on 18 May 2026 carrying a code-signing certificate issued by an entity called "Brittlewort." The name appears nowhere in any public certificate authority registry. It is self-issued, self-signed, and anchored to no trusted root.
#Kimsuky#Guloader#code-signingabuse#spear-phishing#sandboxevasion#Poland#NSISdropper#PEtimestampforgeryActorsKimsuky · Velvet ChollimaIOCf9 · i0 · d0 · u0MITRE18RegionsAU · DE · PLIndustriesAgriculture · Arts & Entertainment · Commercial Services
FILEMembersJun 2, 2026, 02:13 (UTC+9)Two EV Certificates Power Dual-Brand VPN Malware Evading Sandboxes
Seven Windows executables masquerading as legitimate VPN software — split across two distinct product families, WireVPN and VPNMaster — are circulating with valid Extended Validation code-signing certificates from two separate corporate entities, producing clean sandbox verdicts even as antivirus engines flag them at rates between 10 and 35 out of 76.
#Barium#APT15#WireVPN#VPNMaster#EVcode-signingabuse#sandboxevasion#foodandbeveragessector#trojanisedVPNsoftwareActorsBarium · Wicked SpiderIOCf15 · i8 · d25 · u3MITRE20IndustriesFood & Beverages
FILEMembersJun 1, 2026, 22:08 (UTC+9)Fake VPN Trojans Keep Two Invalid EV Certs Alive as Hosts Vanish
Seven Windows binaries circulating as fake VPN and proxy utilities are still riding on the same two Extended Validation code-signing identities they carried the last time CTX Team looked at this cluster — even though 22 domains, six IPs and three URLs have vanished from the campaign's front-end footprint since then. The payload side hasn't moved an inch: every signed sample in both families carries a leaf certificate that VirusTotal's chain validator flags as "not time valid," and every one of…
#code-signingabuse#EVcertificatereuse#WireVpn#VPNMaster#trojan.jumper#PUP#netfilterdriver#proxymalwareActorsBarium · Wicked SpiderIOCf15 · i2 · d3 · u0MITRE20IndustriesFood & Beverages
FILEMembersJun 1, 2026, 18:25 (UTC+9)XWorm Campaign Adds Bulletproof C2 Node on Freshly Registered Hosting
A new command-and-control node anchored to Freakhosting Ltd — a hosting provider whose RIPE block was allocated only on 2025-10-21 and whose organisation was registered as recently as 2026-01-22 — has been added to an ongoing XWorm RAT campaign that CTX Team has been tracking across multiple snapshots. The IP, 143.20.134.59, sits in the 143.20.134.0/24 network on ASN 215703 and carried just 3 of 91 engine detections at the time of analysis, meaning it was effectively invisible to the…
#XWorm#DarkTortilla#PureLogStealer#bulletproofhosting#dynamicDNS#manufacturingsector#purchase-orderlure#C2infrastructureIOCf11 · i1 · d0 · u1MITRE33RegionsAT · AU · BS · CAIndustriesChemicals · Commercial Services · Construction
FILEMembersJun 1, 2026, 12:10 (UTC+9)Four-Detection BAT Stager Opens Door to Czech Utilities via Bitbucket CDN
An 8-kilobyte DOS batch file that only four of 76 antivirus engines flag at submission time is the opening move in a campaign targeting Czech utilities infrastructure — and the low detection count is not an accident. The file, nott.bat, carries two YARA rule hits that expose its construction: SUSP_PS1_JAB_Pattern_Jun22_1, which detects UTF-16 and Base64-encoded PowerShell opening with a single-character variable, and Base64_Encoded_URL, which fires on embedded encoded URI strings.
#trojan.msil/jalapeno#Alien#CzechRepublic#utilitiessector#Bitbucketabuse#ZeroSSLC2#BATstager#PowerShelldownloaderIOCf15 · i2 · d0 · u0MITRE34RegionsCZIndustriesUtilities
FILEMembersJun 1, 2026, 07:20 (UTC+9)Scully Spider's 14-File Catalog Reveals a Decade of Mandatory Packing
Fourteen executable files. Six malware families spanning nearly two decades of Windows-targeting tradecraft. No shared infrastructure, no code-signing certificates, no passive DNS to pivot on — and yet a single, unmistakable operational signature runs through every destructive payload in the set: before anything reaches a victim machine, it gets packed.
#ScullySpider#TA547#UPXpacking#reflectiveDLLloading#CryptoWall#Rokku#Zloader#defenseevasionActorsScully Spider · TA547IOCf14 · i0 · d0 · u0MITRE8
FILEPublicJun 1, 2026, 01:53 (UTC+9)FUZZBUNCH Toolkit Bundles EternalBlue and DarkPulsar in Single APT40 Package
Nineteen files. One deployable directory tree. A complete offensive capability spanning SMB exploitation, kernel-level persistence, Tor-routed command-and-control, and a Python orchestration layer — all assembled from components whose PE compile timestamps span more than a decade of development. The FUZZBUNCH/ShadowBrokers toolkit now attributed in CTX Team's tracking to APT40, with healthcare flagged as the targeted sector, is not a collection of loosely related tools.
#APT40#EternalBlue#DarkPulsar#FUZZBUNCH#ShadowBrokers#healthcaresector#SMBexploitation#kernelbackdoorActorsAPT40 · MudcarpIOCf19 · i0 · d0 · u0IndustriesHealthcare
FILEMembersMay 31, 2026, 21:00 (UTC+9)APT28 Deploys 11-Year-Old Signed Kernel Driver in Layered Credential-Theft Campaign
A financially themed ZIP archive named HSBC_PAYMENT_ADVICE0293845678.zip is circulating as the opening move in a layered attack chain that deploys a signed vulnerable kernel driver first seen in 2015 alongside a freshly compiled DLL sideloading payload and an AgentTesla infostealer equipped with active sandbox-evasion logic.
#APT28#AgentTesla#BYOVD#xkpsm.sys#DLLsideloading#financialsector#credentialtheft#kerneldriverabuseActorsAPT28 · StrontiumIOCf43 · i0 · d0 · u0MITRE27RegionsAE · AT · AU · BDIndustriesConstruction · Engineering · Financial Services
FILEMembersMay 31, 2026, 18:27 (UTC+9)Trojanised BitComet Campaign Engineers 33-Engine Detection Gap via Shared Certificate
##A Certificate Hiding in Plain Sight: How a Trojanised BitComet Campaign Engineers Its Own Detection Gap Five Windows executables. Two code-signing identities. One AWS CloudFront subdomain. And a payload chain carefully tuned so that the component most likely to reach an endpoint registers a detection rate of just 2 out of 76 antivirus engines — while its outer wrapper, signed by the same certificate, flags on 35. That arithmetic is not an accident.
#DealPly#OfferCore#code-signingabuse#CDNfronting#sandboxevasion#adware#financialservices#CloudFrontIOCf58 · i4 · d1 · u0MITRE4RegionsAD · AE · AL · ARIndustriesArts & Entertainment · Education & Research · Financial Services
FILEMembersMay 31, 2026, 18:12 (UTC+9)Conduit-Signed Adware Dropper Achieved 6/54 Detections With Stomped Timestamps and C2 Victim Profiling
A 1.28 MB Windows executable signed with a then-valid Conduit Ltd. code-signing certificate achieved just 6 of 54 possible antivirus detections while concealing a compressed multi-payload bundle in a resource section registering entropy of 8.0 — the maximum possible for a randomly distributed byte stream. That single file, the entry point for a vigram-family adware campaign targeting technology-sector users in Spain, illustrates a layered evasion architecture that goes well beyond commodity…
#vigram#adware#code-signingabuse#browserhelperobject#PEtimestampstomping#Spain#technologysector#C2victimprofilingIOCf17 · i1 · d1 · u2MITRE22RegionsESIndustriesTechnology
FILEPublicMay 31, 2026, 09:27 (UTC+9)Plesk Default Certificate Exposes All Eight LummaStealer C2 Domains
Eight command-and-control domains serving an active LummaStealer campaign share a single Let's Encrypt TLS certificate whose subject common name reads admiring-poincare.37-77-150-150.plesk.page — the auto-generated Plesk control-panel hostname for the raw IP address 37.77.150.150, hosted on Proton66 OOO (ASN 198953) in Russia.
#LummaStealer#Pleskcertificatefingerprint#Proton66OOO#LOLBinimpersonation#code-signingchaingrafting#technologysectortargeting#Spain#MexicoIOCf18 · i1 · d9 · u17MITRE25RegionsES · MXIndustriesTechnology
FILEMembersMay 30, 2026, 23:44 (UTC+9)Gold Evergreen's Vidar Variant Hits Indonesia With Six-Layer Evasion Stack
A 1.41-megabyte unsigned Win32 executable, packed to near-maximum entropy and fetched silently through an Internet Explorer cache path, is at the centre of a credential-theft operation targeting Windows users in Indonesia. The payload — confirmed as a Vidar stealer variant by three independent YARA rules and a Zenbox sandbox classification of MALWARE/STEALER/TROJAN/EVADER at 100% confidence — does not simply steal and exfiltrate.
#GoldEvergreen#Vidarstealer#Arkeistealer#sandboxevasion#cryptocurrencywalletharvesting#dual-channelC2#Indonesia#credentialtheftActorsGold Evergreen · Business ClubIOCf1 · i0 · d0 · u4MITRE11RegionsID
FILEMembersMay 30, 2026, 21:27 (UTC+9)Patchwork Hides Kernel Driver and Crypto Miner in Pirated Game Crack
A 496-megabyte file masquerading as a Football Manager 2024 crack is the entry point for one of the more technically layered campaigns CTX Team has recently dissected — a multi-stage operation attributed to Patchwork that bundles a Bring-Your-Own-Vulnerable-Driver kernel exploit, a cryptocurrency miner dressed as a Windows system binary, and a persistent obfuscation pipeline, all delivered through the oldest social-engineering lure in the book: pirated software.
#Patchwork#BYOVD#WinRing0x64#XMRig#AutoIT#cryptocurrencymining#telecomsector#kernelexploitationActorsPatchwork · ChinastratsIOCf16 · i0 · d0 · u0MITRE41RegionsAU · BR · CM · ITIndustriesTelecommunications
FILEMembersMay 30, 2026, 21:15 (UTC+9)Fake Adobe Plugin Delivers Lumma Stealer and Cryptominer via Four-Layer Chain
A single typosquat domain — adobe-plugin.info — sits at the front of a payload chain that is considerably more engineered than its lure suggests. Behind the Adobe branding lies a structured, automated build pipeline producing at least four distinct malware components: a GCleaner MSIL trojan, a PEiD-packed dropper variant, a compact Nitol persistence stub, and a dual-purpose monetisation stage that runs Lumma stealer and a cryptominer simultaneously on the same compromised host.
#BlueBottle#Lummastealer#CoinMiner03#Nitol#GCleaner#typosquatting#creativeandmediasector#ZIPdropperActorsBlueBottle · Opera1erIOCf13 · i0 · d1 · u1RegionsUS
FILEMembersMay 30, 2026, 17:21 (UTC+9)XWorm RAT Hides C2 Behind Three Evasion Gates in RFQ Phishing Wave
A pair of Windows executables disguised as purchase-order documents began circulating on 7 May 2026, carrying a commodity remote-access trojan wrapped in enough evasion machinery to slip past automated analysis pipelines and arrive on victim systems with its command-and-control address still largely unknown to the industry. The campaign — tracked by CTX Team under the identifier CTXk3fv3k5gux — delivers XWorm RAT via a ZIP archive whose sole contents are a batch script named to mimic a…
#XWorm#SpyEx#procurementphishing#sandboxevasion#ip-api.comhosting-providercheck#energysector#manufacturingsector#commodityRATIOCf4 · i1 · d0 · u1MITRE40RegionsAL · AU · BD · CAIndustriesEnergy · Manufacturing · Retail
FILEMembersMay 30, 2026, 11:53 (UTC+9)Signed LummaStealer Bundle Clears 76 AV Engines With DigiCert Certificate
Five Windows executables carrying a valid, unexpired Reason Cybersecurity Inc. code-signing certificate — all signed in a single session at 08:53 AM on May 26, 2026, under DigiCert Trusted G4 certificate serial 07 8A A6 13 E0 E5 D5 AB 31 96 67 B9 3D 2B 96 73 — have been circulating as the payload core of a LummaStealer distribution campaign that achieves zero detections across 76 antivirus engines. The delivery vehicle is a trojanised uTorrent installer signed by BitTorrent Inc.
#LummaStealer#code-signingabuse#certificateevasion#uTorrentlure#CDNmasquerade#credentialtheft#scheduledtaskpersistence#DigiCertIOCf67 · i4 · d1 · u0MITRE49RegionsAE · AR · AT · AUIndustriesConsulting · Education & Research · Telecommunications
FILEMembersMay 30, 2026, 07:30 (UTC+9)Pay-Per-Install Campaign Adds CryptOne Dropper and Two C2 Domains in Nine Days
Since CTX Team's earlier coverage of this pay-per-install operation, the campaign has added ten new file indicators, stood up two freshly provisioned command-and-control domains within nine days of each other in May 2026, and introduced a raw-IP payload-delivery endpoint on a Netherlands-based host whose TLS certificate presents a deliberately misleading identity.
#pay-per-install#CryptOne#Microleavesadware#ORYONTECHLIMITED#OmegatechLTD#EVcertificateabuse#fakecrackedsoftware#NetherlandsC2infrastructureIOCf23 · i1 · d3 · u6MITRE31RegionsBR · EG · GB · PLIndustriesTechnology
FILEMembersMay 30, 2026, 01:34 (UTC+9)Frozen RAT Builder, Free DNS Alias Keep klovbot Active Since 2017
Sixteen Windows PE32 executables tied to the klovbot malware family are circulating against technology-sector targets in Moldova, and the most operationally revealing detail about the campaign is not the payload — it is the degree to which the operator has changed almost nothing since at least 2017. Three of those files carry enough metadata for deep analysis, and what that analysis surfaces is a tradecraft combination that has outlasted most of the defensive signatures written against it: an…
#klovbot#DarkKomet#XRed#dynamicDNS#Moldova#technologysector#sandboxevasion#USBspreaderIOCf16 · i1 · d0 · u0MITRE24RegionsMDIndustriesTechnology
FILEMembersMay 29, 2026, 14:42 (UTC+9)Single Sectigo EV Certificate Signs Four Malicious Payloads in One Batch
Four malicious Windows executables — spanning PE32, PE32+, and MSI formats, collectively masquerading as a legitimate system utility suite called "Advanced Windows Manager" — were signed with a single valid Sectigo Extended Validation code-signing certificate in one batch event on the morning of 23 April 2026. The certificate, issued to an entity named "ORYON TECH LIMITED" under the Sectigo Public Code Signing CA EV R36 chain (serial 21 E3 D5 C7 00 22 7E A0 2E E6 84 AF 4F 8F 88 40, thumbprint…
#ORYONTECHLIMITED#GCleaner#EvilCh/CryptOne#pay-per-install#EVcertificateabuse#code-signing#Egypt#UnitedKingdomIOCf23 · i1 · d3 · u7MITRE48RegionsEG · GBIndustriesTechnology
FILEMembersMay 29, 2026, 06:45 (UTC+9)One .NET Builder, Two Malware Families, One Turkish C2 IP
A single PE import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the forensic thread that ties together what initially appears to be two separate commodity malware campaigns. On one end sits a 239-kilobyte AgentTesla infostealer, first submitted to VirusTotal in December 2025 and confirmed malicious by all three sandboxes that analysed it.
#agenttesla#HospitalityLeisure#TechnologyIOCf21 · i1 · d0 · u1MITRE41RegionsMA · TRIndustriesHospitality & Leisure · Technology
FILEMembersMay 29, 2026, 02:45 (UTC+9)Packed .NET Stealer Hits Healthcare in 7 Countries With Sandbox-Aware Evasion
A 593-kilobyte .NET assembly, unsigned and unremarkable in appearance, has been circulating against healthcare organisations across Belgium, India, Italy, Sri Lanka, Pakistan, Tunisia, and the United States since at least March 2026. What makes it analytically interesting is not its payload — credential theft is commodity work — but the layered effort its operators invested in making sure analysts never get a clean look at it.
#HealthcareIOCf3 · i1 · d0 · u1MITRE24RegionsBE · IN · IT · LKIndustriesHealthcare
FILEMembersMay 28, 2026, 23:13 (UTC+9)Amadey Loader Hits Academic Networks Across 11 Countries via IE5 Cache
A freshly submitted Win32 executable — unsigned, just over 2 MB, first observed on VirusTotal on 2026-05-07 — is delivering a credential-harvesting payload to education and research institutions across eleven countries, using a staging chain that exploits legacy Internet Explorer cache paths, embeds a secondary payload in the binary's overlay section, and beacons home over raw HTTP to a single IPv4 address on a Seychelles-registered autonomous system that was provisioned less than nine months…
#APT28#EducationResearchActorsAPT28 · StrontiumIOCf2 · i1 · d0 · u1MITRE25RegionsBA · BO · CO · INIndustriesEducation & Research
FILEMembersMay 28, 2026, 22:59 (UTC+9)Expired 2017 Certificate Still Powers Process Hacker 2 Offensive Toolkit
Seventeen Windows executables — two main GUI binaries, a kernel-mode driver, a PE viewer, and thirteen plugin DLLs — have been assembled into a unified offensive package and are circulating with Authenticode signatures that expired in January 2017. The signing identity is "Wen Jia Liu," issued under two DigiCert certificate serials that together bind every file in the toolkit to a single developer lineage.
#RoyalRansomware#CommentCrew#glasses#prochackActorsRoyal Ransomware · Team OneIOCf19 · i0 · d0 · u0MITRE10
FILEMembersMay 28, 2026, 19:00 (UTC+9)Fake Windows DLL Targets Singapore Construction Firms in 16-Year Campaign
A 43-kilobyte Windows DLL masquerading as the operating system's own language-pack library is at the centre of an active implant chain targeting Singapore's construction sector — a toolkit that combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence into a layered evasion architecture that has remained operationally relevant from its first recorded submission in July 2010 through at least May 2026.
#GoblinPanda#avzhan#ConstructionActorsGoblin Panda · CycldekIOCf2 · i0 · d0 · u0MITRE23RegionsSGIndustriesConstruction
FILEMembersMay 28, 2026, 18:49 (UTC+9)Signed VPN Installer Trojan Targets Food and Beverage Firms
Three Windows executables — VPNMaster.exe, Startup.exe, and master_vpn-service.exe — are circulating as components of a coherent VPN product installation, each carrying a DigiCert G4 code-signing certificate issued to a Singapore-registered entity called "INNOVATIVE CONNECTING PTE. LIMITED." The certificate, serial number 0C 8F 89 21 C5 36 49 3E 67 DF 84 FB 82 23 B0 92, expired on 2 April 2026, yet the binaries remain structurally signed and continue to bypass security controls on systems that…
#Barium#APT15#Cactus#ramnit#FoodBeveragesActorsBarium · Wicked SpiderIOCf14 · i1 · d6 · u1MITRE7IndustriesFood & Beverages
FILEMembersMay 28, 2026, 14:45 (UTC+9)APT28's Three-Signer Chain Leaves Four Files at Zero Detections
Eight Windows executables. Three separate trusted signing identities. Four files sitting at zero detections across 76 antivirus engines. The campaign that CTX Team has been tracking under the RostPay/RostDown family designation is not a blunt-force intrusion operation — it is a methodical exercise in trust subversion, engineered so that the failure of any single certificate or detection rule leaves at least two other evasion layers intact.
#APT28#nitol#ghost#CommercialActorsAPT28 · StrontiumIOCf8 · i2 · d0 · u0MITRE11IndustriesCommercial Services
FILEMembersMay 28, 2026, 10:58 (UTC+9)XWorm Campaign Expands to Three-Channel C2 Fabric Across Offshore ASNs
Since CTX Team's earlier coverage of this XWorm campaign, two freshly provisioned command-and-control nodes have surfaced in RIPE NCC address space allocated in late 2025 — 158.94.209.22 under ASN 202412 (Omegatech LTD, Seychelles-registered) and 143.20.134.59 under ASN 215703 (Freakhosting Ltd, nominally UK-registered) — alongside a new dynamic DNS endpoint, jar5.ydns.eu, that carries no VirusTotal detection data at all.
#Commercial#Government#Manufacturing#Media#SupportServiceActivities#TechnologyIOCf12 · i2 · d0 · u1MITRE33RegionsAT · BE · BS · CAIndustriesCommercial Services · Government · Manufacturing
FILEMembersMay 28, 2026, 02:47 (UTC+9)KMSpico Trojan Chain Delivers LummaStealer to Kenya's Tech Sector
Four Windows executables carrying the same self-issued code-signing certificate have been circulating as KMSpico software activators for nearly a decade — and CTX Team's analysis of a recently surfaced indicator cluster shows that the same @ByELDI Certificate Authority, serial number CB C9 53 5C 7A 4B 70 DE 52 6C 01 39 FE AF 2C 9C, still binds the distribution chain today.
#LazarusGroup#lummastealer#TechnologyActorsLazarus Group · Hastati GroupIOCf17 · i1 · d0 · u0MITRE42RegionsKEIndustriesTechnology
FILEPublicMay 28, 2026, 02:32 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Telecom Cryptomining Campaign
Compiled on April 16, 2026, and submitted to VirusTotal just two days later, an unsigned 2.5-megabyte Windows executable is doing something that should give pause to every security team protecting telecommunications infrastructure: it is loading a kernel driver that was signed in 2008, whose Authenticode certificate expired that same year, and whose vulnerabilities have been publicly catalogued for years — and using that driver to claw its way to ring-zero privilege before beaconing out to a…
#LazarusGroup#BYOVD#WinRing0x64#cryptomining#telecommunications#LOLDrivers#privilegeescalation#HashVaultActorsLazarus Group · Hastati GroupIOCf4 · i1 · d0 · u0MITRE31RegionsAR · BG · BR · GRIndustriesTelecommunications
FILEMembersMay 27, 2026, 10:29 (UTC+9)One Imphash, Two Malware Families: Inside a Shared .NET Builder
A purchase-order-themed spear-phishing campaign active since mid-May 2026 has delivered something more operationally revealing than its commodity tooling alone would suggest: two functionally distinct malware families — XWorm RAT and AgentTesla infostealer — sharing an identical PE import-table hash (imphash f34d5f2d4577ed6d9ceec516c1f5a744) and the same PEiD packer signature, confirming both were produced by a single .NET builder kit or shared loader stub.
#agenttesla#Automotive#Commercial#Construction#EducationResearch#EnergyIOCf9 · i1 · d0 · u1MITRE53RegionsAT · AU · BD · BEIndustriesAutomotive · Commercial Services · Construction
FILEPublicMay 27, 2026, 06:47 (UTC+9)Gamaredon Hides Credential-Stealer in Trojanized Driver Utility
A 39-megabyte Windows installer masquerading as the legitimate Easeware DriverEasy driver-update utility is circulating with a forged compile timestamp, a near-maximum-entropy resource section concealing an encrypted payload, and two Dotfuscator-obfuscated .NET implant components built in the same toolchain session — a layered evasion architecture that CTX Team has attributed to Gamaredon Group and linked to construction-sector targeting.
#GamaredonGroup#gamaredon#ConstructionActorsGamaredon Group · CTIGIOCf4 · i0 · d0 · u0MITRE27IndustriesConstruction
FILEMembersMay 27, 2026, 01:21 (UTC+9)XWorm Worm Campaign Hits 24 Countries via Spanish Quotation Lure
A 914-kilobyte Windows executable masquerading as a Spanish-language purchase-order request is circulating across 24 countries, carrying a payload combination that goes well beyond what most commodity-RAT deployments attempt: XWorm and PureLog Stealer bundled together, wrapped in a PEiD-packed binary with a .text section entropy of 7.83, and equipped with a worm-propagation module that can copy the infection to removable media without any additional operator action.
#BusinessAssociations#Chemicals#Construction#Engineering#Government#ManufacturingIOCf12 · i2 · d0 · u1MITRE32RegionsAT · BE · CA · CHIndustriesBusiness Associations · Chemicals · Construction
FILEMembersMay 27, 2026, 00:53 (UTC+9)APT28 Hides Espionage Chain Inside Piracy Activation Toolkit
Seventeen files. One freshly minted domain. A Moldovan hosting provider with a near-clean reputation score. On the surface, the package looks like something millions of Windows users have downloaded without a second thought: a piracy toolkit for activating unlicensed Microsoft software. Look past the familiar filenames and the campaign reveals something considerably more deliberate — a multi-layer espionage delivery chain attributed by CTX Team to APT28, the Russian state-aligned threat actor…
#APT28#powershell#TelecommunicationsActorsAPT28 · StrontiumIOCf17 · i1 · d1 · u0MITRE15IndustriesTelecommunications
FILEMembersMay 26, 2026, 17:21 (UTC+9)APT27's KMS Activator Hides a Five-Year Evasion Framework
Six Windows executables. A self-extracting archive dressed as a software licence tool. A private certificate authority whose validity window stretches to 31 December 2039. Taken individually, each component of this toolset could be dismissed as a grey-market activation utility — the kind of software that circulates freely in environments where Windows licences are expensive and enforcement is lax.
#APT27#expiro#GovernmentActorsAPT27 · TEMP.HippoIOCf6 · i0 · d0 · u0MITRE23IndustriesGovernment
FILEMembersMay 26, 2026, 11:35 (UTC+9)Expired UltraSurf Certificate Powers Stealthy C2 Campaign Against Finance
A UPX-packed Windows executable masquerading as the UltraSurf censorship-circumvention tool — signed with a GlobalSign-issued code-signing certificate that expired in June 2024 but still carries enough historical trust to fool the majority of the antivirus ecosystem — is being used to establish covert command-and-control tunnels toward freshly stood-up infrastructure on Hurricane Electric's network.
#MuddyWater#SilentChollima#Dalbit#hive#FinancialActorsMuddyWater · TEMP.ZagrosIOCf11 · i1 · d0 · u0IndustriesFinancial Services
FILEMembersMay 26, 2026, 11:05 (UTC+9)Vessel-Doc Phishing Campaign Adds Uncharacterised Hashes, Core Tradecraft Unchanged
A 901-kilobyte ZIP archive named MV_NATHAN_VSL_MAIN_PARTICULARS+Q88_DETAILS.zip is doing quiet work across at least thirteen countries. The file — first seen on VirusTotal on 2026-05-13 and submitted from two independent sources on the same day — carries a single embedded PE32 .NET assembly whose .text section registers entropy of 7.88, near the theoretical maximum, and declares zero imports.
#AgentTesla#APT29#MSILstealer#maritimesector#spearphishing#geolocationevasion#packed.NET#credentialtheftActorsAPT29 · MinidionisIOCf4 · i0 · d0 · u0MITRE47RegionsAU · CZ · DE · EGIndustriesEngineering · Financial Services · Manufacturing
FILEMembersMay 24, 2026, 17:57 (UTC+9)Snowglobe Backdoor Hides in GTA V Launcher to Hit Thai Telecoms
A 32-bit Windows executable named "Grand Theft Auto V Enhanced.exe" — one of four GTA V-branded filename variants circulating in this campaign — is not what it claims to be. Behind the high-recognition game title sits a Babar-family backdoor attributed to the Snowglobe actor cluster (also tracked as Animal Farm and Sig20), directed at telecommunications operators in Thailand under an espionage mandate.
#Snowglobe#babar#TelecommunicationsActorsSnowglobe · Animal FarmIOCf4 · i0 · d1 · u0MITRE21RegionsTHIndustriesTelecommunications
FILEMembersMay 24, 2026, 15:23 (UTC+9)Revoked EV Cert and CloudFront CDN Power 32-Country Installer Campaign
Two Windows PE32 installers, both bearing a Sectigo Extended Validation code-signing certificate issued to an entity called "Plooto Star Inc," were signed within sixty seconds of each other on the afternoon of September 21, 2025 — and by the time either file appeared on VirusTotal five days later, that certificate had already been revoked by its issuer.
#DustSquad#lummastealer#Consulting#EducationResearch#Financial#GovernmentActorsDustSquad · APTC34IOCf2 · i0 · d1 · u0MITRE18RegionsBJ · BR · CI · ECIndustriesConsulting · Education & Research · Financial Services