CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • C&CMembersMay 27, 2026, 21:54 (UTC+9)

    Six-Year-Old Batch Script Powers 2025 Telecom Espionage Campaign

    A trojanised ZIP archive impersonating the legitimate Microsoft Activation Scripts open-source project is circulating across enterprise endpoints, embedding active sandbox-evasion logic inside what victims perceive as a trusted Windows activation utility — and funnelling compromised hosts toward a freshly constructed, deliberately compartmentalised command-and-control infrastructure spanning three distinct autonomous systems with no cross-node certificate or DNS linkage between them.

    #TA505#Cactus#goldeneye#Telecommunications
    ActorsTA505 · Hive0065IOCf2 · i2 · d1 · u17MITRE4IndustriesTelecommunications
  • C&CMembersMay 27, 2026, 18:11 (UTC+9)

    WireVPN Campaign Adds 132 Domains and a PBot Stealer Component

    Fifty-five new command-and-control IPs and 132 additional domains have joined the Trojan.Jumper/WireVPN campaign's observable footprint since CTX Team's earlier coverage, transforming what was a 15-domain, 9-ASN operation into a multi-continent hosting fabric organised across five named fingerprint clusters. The expansion is not random: every cluster is bound by a shared certificate issuer, autonomous system, or registrar identity, and the core payload chain — three PE32 executables all signed…

    #SpacePirates#Cactus
    ActorsSpace Pirates · WebwormIOCf4 · i55 · d132 · u19MITRE14
  • C&CMembersMay 27, 2026, 17:56 (UTC+9)

    Salty Spider Expands to Dual-Domain C2 With UnionPay TLS Fingerprint

    Nine command-and-control domains, nine documented URL paths, and 31 IP addresses — none present in prior coverage — have surfaced in the latest observed activity tied to the Salty Spider campaign, exposing for the first time the full operational infrastructure behind a signed-binary adware toolkit that CTX Team has been tracking across multiple observation windows.

    #SaltySpider#lummastealer#sality
    ActorsSalty Spider · KuKuIOCf51 · i31 · d9 · u9MITRE8
  • C&CMembersMay 27, 2026, 13:52 (UTC+9)

    Trojan.Jumper Builds Five-Tier C2 Across 15 Domains and 9 ASNs

    Fifteen new domains. Nine IP addresses spanning six autonomous systems across four continents. Five distinct certificate-issuer fingerprints provisioned within a 45-day window. Since CTX Team's earlier coverage of the Trojan.Jumper campaign, the operator has not merely maintained an existing footprint — they have constructed a layered, multi-tier command-and-control architecture that reveals a level of infrastructure investment inconsistent with opportunistic or low-sophistication adversaries.

    #Government
    IOCf4 · i9 · d15 · u4MITRE18IndustriesGovernment
  • FILEMembersMay 27, 2026, 10:29 (UTC+9)

    One Imphash, Two Malware Families: Inside a Shared .NET Builder

    A purchase-order-themed spear-phishing campaign active since mid-May 2026 has delivered something more operationally revealing than its commodity tooling alone would suggest: two functionally distinct malware families — XWorm RAT and AgentTesla infostealer — sharing an identical PE import-table hash (imphash f34d5f2d4577ed6d9ceec516c1f5a744) and the same PEiD packer signature, confirming both were produced by a single .NET builder kit or shared loader stub.

    #agenttesla#Automotive#Commercial#Construction#EducationResearch#Energy
    IOCf9 · i1 · d0 · u1MITRE53RegionsAT · AU · BD · BEIndustriesAutomotive · Commercial Services · Construction
  • FILEPublicMay 27, 2026, 06:47 (UTC+9)

    Gamaredon Hides Credential-Stealer in Trojanized Driver Utility

    A 39-megabyte Windows installer masquerading as the legitimate Easeware DriverEasy driver-update utility is circulating with a forged compile timestamp, a near-maximum-entropy resource section concealing an encrypted payload, and two Dotfuscator-obfuscated .NET implant components built in the same toolchain session — a layered evasion architecture that CTX Team has attributed to Gamaredon Group and linked to construction-sector targeting.

    #GamaredonGroup#gamaredon#Construction
    ActorsGamaredon Group · CTIGIOCf4 · i0 · d0 · u0MITRE27IndustriesConstruction
  • APTMembersMay 27, 2026, 06:02 (UTC+9)

    Trojanised Office Tool Hides Multi-Stage Intrusion Behind Streaming C2

    A trojanised version of OfficeRTool — a popular Microsoft Office removal and activation utility distributed through piracy channels — is serving as the entry point for a disciplined, multi-phase intrusion operation that layers sandbox-evading VBScript components, a vhash-identical PowerShell downloader maintained across at least six major tool versions, expired-certificate network reconnaissance, and a command-and-control channel engineered to look indistinguishable from HLS media streaming…

    #LockbitGang#expiro#Government
    ActorsLockbit GangIOCf7 · i3 · d2 · u8MITRE11IndustriesGovernment
  • APTMembersMay 27, 2026, 05:51 (UTC+9)

    Expired-Cert Installer Evades Sandboxes, Feeds 15-Domain Crypto Fraud Net

    A 4.3-megabyte Windows installer, dressed in the branding of legitimate freeware and carrying a Sectigo-issued code-signing certificate that had already expired, is the entry point for a financially motivated campaign that routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains.

    #APT28#APT15#bumblebee#Energy
    ActorsAPT28 · StrontiumIOCf62 · i6 · d15 · u11MITRE12IndustriesEnergy
  • FILEMembersMay 27, 2026, 01:21 (UTC+9)

    XWorm Worm Campaign Hits 24 Countries via Spanish Quotation Lure

    A 914-kilobyte Windows executable masquerading as a Spanish-language purchase-order request is circulating across 24 countries, carrying a payload combination that goes well beyond what most commodity-RAT deployments attempt: XWorm and PureLog Stealer bundled together, wrapped in a PEiD-packed binary with a .text section entropy of 7.83, and equipped with a worm-propagation module that can copy the infection to removable media without any additional operator action.

    #BusinessAssociations#Chemicals#Construction#Engineering#Government#Manufacturing
    IOCf12 · i2 · d0 · u1MITRE32RegionsAT · BE · CA · CHIndustriesBusiness Associations · Chemicals · Construction
  • FILEMembersMay 27, 2026, 00:53 (UTC+9)

    APT28 Hides Espionage Chain Inside Piracy Activation Toolkit

    Seventeen files. One freshly minted domain. A Moldovan hosting provider with a near-clean reputation score. On the surface, the package looks like something millions of Windows users have downloaded without a second thought: a piracy toolkit for activating unlicensed Microsoft software. Look past the familiar filenames and the campaign reveals something considerably more deliberate — a multi-layer espionage delivery chain attributed by CTX Team to APT28, the Russian state-aligned threat actor…

    #APT28#powershell#Telecommunications
    ActorsAPT28 · StrontiumIOCf17 · i1 · d1 · u0MITRE15IndustriesTelecommunications
  • APTMembersMay 27, 2026, 00:03 (UTC+9)

    APT28 Splits EV Certificate and LummaC2 Stealer Across Two-Tier Chain

    Four Windows executables carrying a valid Extended Validation code-signing certificate issued to an entity called ORYON TECH LIMITED are circulating as a disguised system-utility package — while a pair of freshly compiled LummaC2 stealers, deliberately stripped of any trusted certificate chain, rides the same delivery infrastructure toward the same targets. The deliberate split is not an oversight.

    #APT28#gcleaner#Technology
    ActorsAPT28 · StrontiumIOCf21 · i2 · d5 · u8RegionsUSIndustriesTechnology
  • APTMembersMay 26, 2026, 23:45 (UTC+9)

    Signed, Sealed, Trojanized: Dual Chengdu Certs Power RAT Campaign

    Eighteen Windows PE32 files — executables and DLLs impersonating Ludashi SuperApp system utilities — are circulating with currently-valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, producing uniformly clean sandbox verdicts despite industry detection ratios that reach as high as 34 of 76 engines.

    #Turla#FIN6#Group123#lockergoga#ncctrojan#xtreme_rat
    ActorsTurla · Iron HunterIOCf57 · i27 · d7 · u1MITRE16IndustriesTelecommunications
  • C&CMembersMay 26, 2026, 22:40 (UTC+9)

    One DigiCert Cert Signed 16 Malicious Binaries Across 18 Months

    Sixteen distinct Windows binaries. Eight separate product personas. One DigiCert code-signing certificate — and not a single revocation in eighteen months. That is the operational core of a sustained adware and data-harvesting campaign that CTX Team has been tracking across the Ludashi (鲁大师) software ecosystem, where malware dressed as Chinese security utilities has been circulating since at least November 2024.

    #TA551#FIN6#Group123#lockergoga#icedid
    ActorsTA551 · ShathakIOCf30 · i25 · d9 · u9MITRE12
  • APTMembersMay 26, 2026, 22:24 (UTC+9)

    FunkSec macOS Implant Evades 76 AV Engines via Fake Chrome Signing

    Two Mach-O universal binaries named com.google.Chrome.helper — each 166 kilobytes, each signed with a structurally present but functionally invalid Google LLC code-signing certificate, each returning zero detections across all 76 antivirus engines on VirusTotal — are circulating as part of a campaign CTX Team has attributed to FunkSec, targeting engineering and government sector organisations operating macOS endpoints.

    #FunkSec#Engineering#Government
    ActorsFunkSecIOCf2 · i12 · d47 · u31MITRE8IndustriesEngineering · Government
  • APTMembersMay 26, 2026, 22:03 (UTC+9)

    Salty Spider Turns Revoked Certificates Into a 71/76 Evasion Tool

    Two Windows executables submitted to public malware repositories on 23 May 2026 — both signed with a code-signing certificate that had already been revoked by its issuing CA — cleared 71 of 76 scanning engines without triggering a single alert. The files, bearing the product description "Pro解压缩" (Pro Decompression) and the internal name uninst.exe, were the freshest output of a campaign that CTX Team has been tracking across a ten-month arc stretching from July 2025 to the present.

    #SaltySpider#sality
    ActorsSalty Spider · KuKuIOCf15 · i1 · d8 · u3MITRE42
  • C&CMembersMay 26, 2026, 21:16 (UTC+9)

    AS214351 Adds 'PureCrack' Relay Node and DGA Domains in C2 Expansion

    Since CTX Team's earlier coverage of this financially motivated campaign — documented then as a raw-IP beaconing operation running six malware families across a single young autonomous system — ten new files, two algorithmically generated domains, and a second command-and-control IP have surfaced. The most operationally significant addition is not another payload variant but a structural change to the hosting fabric itself: 196.251.107.104, a new node within AS214351 operated by Femo IT…

    #AS214351#FemoITSolutions#Stealcv2#BazarLoader#Amadey#clipboardhijacker#bulletproofhosting#DGAdomains
    IOCf20 · i3 · d2 · u5MITRE18RegionsAL · BO · CA · DE
  • C&CMembersMay 26, 2026, 21:02 (UTC+9)

    Dual-Cert Trojan VPN Pipeline Targets Food and Beverage Sector

    Five Windows executables are circulating as components of a legitimate-looking VPN product — each carrying a valid-chain code-signing certificate issued to one of two shell entities, "INNOVATIVE CONNECTING PTE. LIMITED" and "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — while quietly establishing proxy-chain command-and-control infrastructure anchored in a Chengdu internet data centre.

    #Barium#APT15#Cactus#ramnit#FoodBeverages
    ActorsBarium · Wicked SpiderIOCf10 · i18 · d23 · u3MITRE7IndustriesFood & Beverages
  • C&CMembersMay 26, 2026, 20:44 (UTC+9)

    Five Shell Companies, One Adware Campaign: DigiCert Cert Rotation Exposed

    Thirty-one signed Windows binaries. Five distinct Chinese legal entities. One certificate authority. The Ludashi adware ecosystem — distributed under the guise of utility software products with names like LargeFileClean, WhaleMemory, Mem Optimization Pro, DupsClean, and CipherLock — has been running a sustained code-signing rotation strategy that goes well beyond what commodity adware operators typically invest in.

    #FIN6#lockergoga#icedid
    ActorsFIN6 · Skeleton SpiderIOCf31 · i4 · d12 · u8MITRE35
  • FILEMembersMay 26, 2026, 17:21 (UTC+9)

    APT27's KMS Activator Hides a Five-Year Evasion Framework

    Six Windows executables. A self-extracting archive dressed as a software licence tool. A private certificate authority whose validity window stretches to 31 December 2039. Taken individually, each component of this toolset could be dismissed as a grey-market activation utility — the kind of software that circulates freely in environments where Windows licences are expensive and enforcement is lax.

    #APT27#expiro#Government
    ActorsAPT27 · TEMP.HippoIOCf6 · i0 · d0 · u0MITRE23IndustriesGovernment
  • C&CMembersMay 26, 2026, 17:06 (UTC+9)

    Four Signed Certs, Ten IPs, One UnionPay Disguise: IcedID's Dual-Layer Evasion

    Seventeen Windows executables and DLLs, all validly signed by DigiCert's Trusted G4 Code Signing chain, are circulating as system-cleaning and security utilities — and every one of them beacons to a C2 backend whose ten IP addresses present a wildcard TLS certificate issued to UnionPay International Co., Ltd. The combination is not accidental.

    #icedid
    IOCf25 · i10 · d2 · u2MITRE46
  • C&CMembersMay 26, 2026, 16:51 (UTC+9)

    APT28 Burns Fake Cert, Hides Agent Behind Legit Vendor Signature

    Two Windows executables, both signed with a freshly minted code-signing certificate issued to a shell identity called "Work Product Inc.," are circulating as a trojanized browser installer targeting the telecom sector — a signed-binary abuse chain [T1553.002] engineered to walk past execution controls before most endpoint tools have a chance to render a verdict.

    #APT28#njrat#Telecommunications
    ActorsAPT28 · StrontiumIOCf3 · i3 · d3 · u1MITRE6IndustriesTelecommunications
  • APTMembersMay 26, 2026, 16:35 (UTC+9)

    Two DigiCert Certs, 18 Signed Payloads, 14 Months Unrevoked

    Eighteen Windows executables and DLLs have been circulating under the cover of two valid DigiCert Trusted G4 code-signing certificates, each issued to a distinct Chinese legal entity, across a campaign that CTX Team has tracked from November 2024 through at least January 2026. Both certificates remain unrevoked. Every file in the cohort passes Windows Authenticode validation without a SmartScreen warning.

    #FIN6#SaltySpider#lockergoga#lummastealer#sality
    ActorsFIN6 · Skeleton SpiderIOCf32 · i8 · d10 · u12MITRE19
  • FILEMembersMay 26, 2026, 11:35 (UTC+9)

    Expired UltraSurf Certificate Powers Stealthy C2 Campaign Against Finance

    A UPX-packed Windows executable masquerading as the UltraSurf censorship-circumvention tool — signed with a GlobalSign-issued code-signing certificate that expired in June 2024 but still carries enough historical trust to fool the majority of the antivirus ecosystem — is being used to establish covert command-and-control tunnels toward freshly stood-up infrastructure on Hurricane Electric's network.

    #MuddyWater#SilentChollima#Dalbit#hive#Financial
    ActorsMuddyWater · TEMP.ZagrosIOCf11 · i1 · d0 · u0IndustriesFinancial Services
  • FILEMembersMay 26, 2026, 11:05 (UTC+9)

    Vessel-Doc Phishing Campaign Adds Uncharacterised Hashes, Core Tradecraft Unchanged

    A 901-kilobyte ZIP archive named MV_NATHAN_VSL_MAIN_PARTICULARS+Q88_DETAILS.zip is doing quiet work across at least thirteen countries. The file — first seen on VirusTotal on 2026-05-13 and submitted from two independent sources on the same day — carries a single embedded PE32 .NET assembly whose .text section registers entropy of 7.88, near the theoretical maximum, and declares zero imports.

    #AgentTesla#APT29#MSILstealer#maritimesector#spearphishing#geolocationevasion#packed.NET#credentialtheft
    ActorsAPT29 · MinidionisIOCf4 · i0 · d0 · u0MITRE47RegionsAU · CZ · DE · EGIndustriesEngineering · Financial Services · Manufacturing
  • C&CMembersMay 26, 2026, 10:47 (UTC+9)

    Spring Dragon Hides SQL Implant in Signed Netease Emulator, Fools All 76 AV Engines

    A 24-megabyte Windows executable presenting as the legitimate Netease MuMuPlayer Android emulator has cleared every antivirus engine that examined it — all 76 of them — while simultaneously triggering a YARA rule identifying byte patterns consistent with the SKIP-2.0 SQL Server authentication-bypass implant. The binary carries a valid, unrevoked DigiCert-rooted code-signing certificate issued to Netease Interactive Entertainment Pte.

    #SpringDragon#wmi_ghost#EducationResearch#Technology
    ActorsSpring Dragon · Lotus BlossomIOCf2 · i0 · d4 · u1MITRE4IndustriesEducation & Research · Technology
  • C&CMembersMay 26, 2026, 10:27 (UTC+9)

    Two DigiCert Certificates, 16 Malicious Binaries, Nine Months Unrevoked

    Sixteen Windows executables bearing currently-valid DigiCert G4 code-signing certificates have been circulating across Chinese-language software distribution channels since at least August 2025, impersonating disk-cleaners, QQ-cleanup utilities, zip tools, and browser-guard products — a signed-binary abuse chain [T1553.002] that walks past Windows SmartScreen and suppresses the heuristic engines that most enterprise endpoints rely on.

    #TA511
    ActorsTA511 · MAN1IOCf26 · i8 · d3 · u3MITRE4
  • APTMembersMay 26, 2026, 10:12 (UTC+9)

    Trojanized Adware Chain Hides Behind Bank's TLS Identity for 12 Months

    Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 have been circulating as trojanized PC-utility components since at least May 2025 — all signed under a single certificate serial (0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0) that remains unrevoked and valid through May 2027.

    #FIN6#lockergoga#lummastealer#expiro#Telecommunications
    ActorsFIN6 · Skeleton SpiderIOCf20 · i18 · d0 · u1MITRE8IndustriesTelecommunications
  • APTMembersMay 26, 2026, 09:59 (UTC+9)

    Single EV Certificate Signed Trojan.Jumper Trio Across Nine Sectors

    A trojanised VPN installer toolchain — three PE32 binaries all bearing a single GlobalSign Extended Validation certificate issued to "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — has been circulating across nine industry verticals since at least September 2025, using a curated software-recommendation channel as its entry point and a three-tier command-and-control architecture to evade both sandbox analysis and network-level detection.

    #TA551#EducationResearch#Engineering#Financial#FoodBeverages#Government
    ActorsTA551 · ShathakIOCf3 · i4 · d2 · u1MITRE29IndustriesEducation & Research · Engineering · Financial Services
  • APTMembersMay 26, 2026, 09:41 (UTC+9)

    APT23 Runs 18-Month Signed-Binary Campaign Behind Chinese Corporate Certs

    Eight Windows executables have been circulating across Chinese-language computing environments since at least November 2024, each carrying a valid, unexpired DigiCert G4 code-signing certificate issued to one of three distinct Chinese corporate entities — and each producing uniformly clean verdicts in automated sandbox environments despite antivirus detection ratios that range as high as 34 out of 76 engines.

    #APT23#lummastealer#icedid#neshta
    ActorsAPT23 · KeyBoyIOCf12 · i2 · d9 · u11MITRE13
  • APTMembersMay 24, 2026, 17:57 (UTC+9)

    One Unrevoked Certificate, 17 Payloads, Eleven Months of Signed Adware

    Seventeen distinct Windows executables. Six product identities. Eleven months of continuous distribution. All of it bound together by a single DigiCert G4 code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co., Ltd.) — a certificate that, as of this writing, remains valid, unrevoked, and good until May 2027.

    #FIN6#Group123#SaltySpider#lockergoga#lummastealer#sality
    ActorsFIN6 · Skeleton SpiderIOCf34 · i3 · d6 · u6MITRE11
  • C&CMembersMay 24, 2026, 17:57 (UTC+9)

    Six Shell Companies, One Builder: DigiCert Certs Fuelled 14-Month Signed-Malware Run

    Thirty-four Windows executables carrying valid DigiCert Trusted G4 Code Signing certificates — each issued to a distinct Chinese company identity — have been circulating since October 2024, disguised as consumer PC-utility software: file cleaners, memory optimisers, browser protectors, and QQ-related tray applications. The signing identities rotate. The build toolchain does not.

    #FIN6#TA428#lockergoga#ncctrojan#icedid
    ActorsFIN6 · Skeleton SpiderIOCf34 · i13 · d11 · u10MITRE23
  • FILEMembersMay 24, 2026, 17:57 (UTC+9)

    Snowglobe Backdoor Hides in GTA V Launcher to Hit Thai Telecoms

    A 32-bit Windows executable named "Grand Theft Auto V Enhanced.exe" — one of four GTA V-branded filename variants circulating in this campaign — is not what it claims to be. Behind the high-recognition game title sits a Babar-family backdoor attributed to the Snowglobe actor cluster (also tracked as Animal Farm and Sig20), directed at telecommunications operators in Thailand under an espionage mandate.

    #Snowglobe#babar#Telecommunications
    ActorsSnowglobe · Animal FarmIOCf4 · i0 · d1 · u0MITRE21RegionsTHIndustriesTelecommunications
  • FILEMembersMay 24, 2026, 15:23 (UTC+9)

    Revoked EV Cert and CloudFront CDN Power 32-Country Installer Campaign

    Two Windows PE32 installers, both bearing a Sectigo Extended Validation code-signing certificate issued to an entity called "Plooto Star Inc," were signed within sixty seconds of each other on the afternoon of September 21, 2025 — and by the time either file appeared on VirusTotal five days later, that certificate had already been revoked by its issuer.

    #DustSquad#lummastealer#Consulting#EducationResearch#Financial#Government
    ActorsDustSquad · APTC34IOCf2 · i0 · d1 · u0MITRE18RegionsBJ · BR · CI · ECIndustriesConsulting · Education & Research · Financial Services
  • C&CMembersMay 24, 2026, 14:51 (UTC+9)

    APT28 Deploys Validly Signed Chrome Fake, Gets Zero Detections

    A 4-megabyte Windows executable masquerading as Google Chrome is circulating with a valid, unexpired Google LLC code-signing certificate — and every one of the 76 antivirus engines that examined it returned a clean verdict. That single data point, drawn from CTX Team's analysis of a cluster attributed to APT28 (also tracked as Fancy Bear, Forest Blizzard, and approximately 17 other aliases), captures the operational logic of the entire campaign: when a binary carries a legitimate certificate…

    #APT28#Government
    ActorsAPT28 · StrontiumIOCf2 · i1 · d3 · u6MITRE4IndustriesGovernment
  • C&CMembersMay 24, 2026, 14:38 (UTC+9)

    WHQL-Signed Driver Blinds EDR a Year Before Crypto Theft Wave

    A 34-kilobyte Windows kernel driver — signed with a legitimate Microsoft Hardware Compatibility Publisher certificate, bearing Safetica copyright strings, and detected by exactly two of 76 antivirus engines — was quietly staged on victim systems as early as May 2025. Nearly a year later, a coordinated wave of credential stealers, clipboard hijackers, and browser wallet harvesters began appearing in the wild, all beaconing to a two-IP cluster in a small, recently allocated autonomous system.

    #TA428#WizardSpider#pythonstealer#vulcan
    ActorsTA428 · ThunderCatsIOCf25 · i3 · d1 · u9
  • APTMembersMay 24, 2026, 14:01 (UTC+9)

    Salty Spider Hides RAT in Signed Bundles via Two DigiCert Certs

    Twenty malicious Windows executables and DLLs have been circulating under valid DigiCert G4 code-signing certificates issued to two Chinese-registered front entities — a dual-certificate architecture that has remained unrotated across a fifteen-month active build window while the operator quietly embedded a PubNubRAT remote-access capability inside what presents to users as a routine system-utility bundle.

    #SaltySpider#sality
    ActorsSalty Spider · KuKuIOCf33 · i7 · d6 · u5MITRE14
  • APTMembersMay 24, 2026, 13:30 (UTC+9)

    Cactus Group Abuses Three Signing Identities to Hide PBot Stealer in VPN Lures

    Nine Windows executables circulating across software-distribution channels share a single operational logic: every one of them carries a legitimate code-signing certificate — or a certificate that was legitimate until recently — and every one of them is doing something the signer never intended. Six files exploit expired-but-chain-valid EV and OV certificates from two distinct corporate identities to suppress antivirus detection on trojanized VPN installers.

    #Cactus#ramnit
    ActorsCactus · Cactus Ransomware GroupIOCf16 · i46 · d118 · u16MITRE16
1Of
10
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.