CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • FILEMembersJun 1, 2026, 22:08 (UTC+9)

    Fake VPN Trojans Keep Two Invalid EV Certs Alive as Hosts Vanish

    Seven Windows binaries circulating as fake VPN and proxy utilities are still riding on the same two Extended Validation code-signing identities they carried the last time CTX Team looked at this cluster — even though 22 domains, six IPs and three URLs have vanished from the campaign's front-end footprint since then. The payload side hasn't moved an inch: every signed sample in both families carries a leaf certificate that VirusTotal's chain validator flags as "not time valid," and every one of…

    #code-signingabuse#EVcertificatereuse#WireVpn#VPNMaster#trojan.jumper#PUP#netfilterdriver#proxymalware
    ActorsBarium · Wicked SpiderIOCf15 · i2 · d3 · u0MITRE20IndustriesFood & Beverages
  • APTMembersJun 1, 2026, 20:47 (UTC+9)

    Five-Year Cert Rotation Engine Keeps Chinese-Ecosystem Malware Signed

    Nine Windows executables and DLLs masquerading as MultiWeChat, TabX Explorer, Ludashi system utilities, and WPS Office components have been circulating with valid DigiCert code-signing certificates — not because a single company's identity was stolen, but because whoever operates this campaign has maintained sustained access to DigiCert's G4 code-signing infrastructure through six distinct Chinese-registered legal entities across a span of nearly five years.

    #APT28#certificaterotation#codesigningabuse#Ludashi#QJWMonkey#CDNfronting#Chinesesoftwareecosystem#DigiCert
    ActorsAPT28 · StrontiumIOCf11 · i6 · d4 · u1MITRE10
  • FILEMembersJun 1, 2026, 18:25 (UTC+9)

    XWorm Campaign Adds Bulletproof C2 Node on Freshly Registered Hosting

    A new command-and-control node anchored to Freakhosting Ltd — a hosting provider whose RIPE block was allocated only on 2025-10-21 and whose organisation was registered as recently as 2026-01-22 — has been added to an ongoing XWorm RAT campaign that CTX Team has been tracking across multiple snapshots. The IP, 143.20.134.59, sits in the 143.20.134.0/24 network on ASN 215703 and carried just 3 of 91 engine detections at the time of analysis, meaning it was effectively invisible to the…

    #XWorm#DarkTortilla#PureLogStealer#bulletproofhosting#dynamicDNS#manufacturingsector#purchase-orderlure#C2infrastructure
    IOCf11 · i1 · d0 · u1MITRE33RegionsAT · AU · BS · CAIndustriesChemicals · Commercial Services · Construction
  • C&CMembersJun 1, 2026, 17:38 (UTC+9)

    One DigiCert Cert, 22 New Payloads: Inside a Chinese Adware Signing Pipeline

    Since CTX Team's earlier coverage of this operation, twenty-two additional signed Windows executables and five new command-and-control IP addresses have surfaced under the same Chengdu-registered signing identity — all bearing a DigiCert code-signing certificate that remains valid until May 2027 and has not been revoked. The expansion confirms that the operator behind 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co.

    #FIN6#adware#code-signingabuse#LuDaShisideloading#China#DigiCertcertificate#tjbxldkj.cn#consumerendpoint
    ActorsFIN6 · Skeleton SpiderIOCf41 · i13 · d7 · u9MITRE9
  • APTMembersJun 1, 2026, 17:20 (UTC+9)

    Fifteen New Addresses Cluster Inside One China Mobile ASN

    Seventeen IP indicators sit in this record, and fourteen of them are new to this pass. Almost all of them — fifteen of the seventeen — resolve inside a single autonomous system: AS9808, registered to China Mobile Communications Group Co., Ltd. That concentration is the most consequential fact in this update, eclipsing the signed-binary story that anchored earlier coverage of this cluster.

    #SaltySpider#PubNubRAT#AS9808#ChinaMobilecarrierinfrastructure#wildcardTLScertificateabuse#signedadware#codesigningcertificate#CDNspoofing
    ActorsSalty Spider · KuKuIOCf103 · i17 · d1 · u1MITRE17
  • FILEMembersJun 1, 2026, 12:10 (UTC+9)

    Four-Detection BAT Stager Opens Door to Czech Utilities via Bitbucket CDN

    An 8-kilobyte DOS batch file that only four of 76 antivirus engines flag at submission time is the opening move in a campaign targeting Czech utilities infrastructure — and the low detection count is not an accident. The file, nott.bat, carries two YARA rule hits that expose its construction: SUSP_PS1_JAB_Pattern_Jun22_1, which detects UTF-16 and Base64-encoded PowerShell opening with a single-character variable, and Base64_Encoded_URL, which fires on embedded encoded URI strings.

    #trojan.msil/jalapeno#Alien#CzechRepublic#utilitiessector#Bitbucketabuse#ZeroSSLC2#BATstager#PowerShelldownloader
    IOCf15 · i2 · d0 · u0MITRE34RegionsCZIndustriesUtilities
  • APTMembersJun 1, 2026, 10:22 (UTC+9)

    Chengdu Operator Hides RAT Inside Adware Using Dual DigiCert Certs

    Nineteen of twenty Windows executables and DLLs circulating under fake Chinese security-product brands — SafeSpace, ByteLocker, DataVault, LhpMaxProtect, LhpNetSentinel, and a half-dozen others — carry valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, a signed-binary abuse strategy [T1553.002] that drives detection ratios as low as 12 of 76 engines on the largest payloads.

    #PubNubRAT#Ludashi#code-signingabuse#certificateevasion#telecommunicationssector#Chengdu#adware-as-cover#C2infrastructure
    ActorsFIN6 · Skeleton SpiderIOCf54 · i11 · d10 · u14MITRE10IndustriesTelecommunications
  • FILEMembersJun 1, 2026, 07:20 (UTC+9)

    Scully Spider's 14-File Catalog Reveals a Decade of Mandatory Packing

    Fourteen executable files. Six malware families spanning nearly two decades of Windows-targeting tradecraft. No shared infrastructure, no code-signing certificates, no passive DNS to pivot on — and yet a single, unmistakable operational signature runs through every destructive payload in the set: before anything reaches a victim machine, it gets packed.

    #ScullySpider#TA547#UPXpacking#reflectiveDLLloading#CryptoWall#Rokku#Zloader#defenseevasion
    ActorsScully Spider · TA547IOCf14 · i0 · d0 · u0MITRE8
  • C&CMembersJun 1, 2026, 07:00 (UTC+9)

    Salty Spider Pivots to Valid WPS Certificate for Near-Invisible Telecom Implant

    Six Windows executables circulating as VPN and proxy clients are carrying code-signing certificates from two Singapore-registered entities — INNOVATIVE CONNECTING PTE. LIMITED and WEILAI NETWORK TECHNOLOGY CO., LIMITED — whose DigiCert and GlobalSign EV credentials expired in April 2026 yet continue to present intact Authenticode chains that most endpoint controls will not challenge.

    #SaltySpider#code-signingabuse#EVcertificate#VPNMaster#KingsoftWPSOffice#telecommunications#Asia-Pacific#trojanisedinstaller
    ActorsSalty Spider · KuKuIOCf6 · i14 · d39 · u4MITRE13IndustriesTelecommunications
  • C&CMembersJun 1, 2026, 06:27 (UTC+9)

    Ludashi C2 Expands: Two .cn Clusters, Shared IPs, and a New Browser Injector

    Nine new domains and 13 IP addresses have been added to the Ludashi campaign's observable footprint since CTX Team's earlier coverage, and the infrastructure picture they complete is more deliberate than the raw count suggests. Two parallel command-and-control domain families — whnuowo.cn and tjbxldkj.cn — are now fully mapped, their subdomains provisioned in coordinated batches under iTrust DV wildcard certificates, their config endpoints resolving to a single shared IP that stitches the two…

    #Ludashi#FIN6#TA428#MasterBHO#PubNubRAT#browserhelperobject#commandandcontrol#China
    ActorsFIN6 · Skeleton SpiderIOCf31 · i13 · d9 · u6MITRE9
  • FILEPublicJun 1, 2026, 01:53 (UTC+9)

    FUZZBUNCH Toolkit Bundles EternalBlue and DarkPulsar in Single APT40 Package

    Nineteen files. One deployable directory tree. A complete offensive capability spanning SMB exploitation, kernel-level persistence, Tor-routed command-and-control, and a Python orchestration layer — all assembled from components whose PE compile timestamps span more than a decade of development. The FUZZBUNCH/ShadowBrokers toolkit now attributed in CTX Team's tracking to APT40, with healthcare flagged as the targeted sector, is not a collection of loosely related tools.

    #APT40#EternalBlue#DarkPulsar#FUZZBUNCH#ShadowBrokers#healthcaresector#SMBexploitation#kernelbackdoor
    ActorsAPT40 · MudcarpIOCf19 · i0 · d0 · u0IndustriesHealthcare
  • C&CMembersJun 1, 2026, 00:45 (UTC+9)

    Four Corporate Fronts, One Build Pipeline: 18-Month DigiCert Signing Spree

    Fifteen signed Windows executables. Four registered Chinese companies. One DigiCert certificate authority chain threading through all of them. The campaign CTX Team has been tracking across an 18-month window does not rely on a single forged credential or a stolen certificate — it relies on something more durable: a systematic program of acquiring legitimate DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 certificates under distinct corporate identities, then rotating those identities…

    #DigiCertcertificateabuse#Authenticodesigningrotation#PEoverlaytechnique#sandboxevasion#Ludashi#PubNubRAT#Chinesefrontcompanies#consumersoftwarebundling
    IOCf86 · i8 · d1 · u1MITRE25
  • APTMembersMay 31, 2026, 23:52 (UTC+9)

    Void Arachne Splits DigiCert Abuse Across Three Firms to Outrun Revocation

    Eight PE32 executables dressed as consumer disk cleaners and Android emulator components are circulating with valid DigiCert G4 code-signing certificates obtained under three distinct Chinese legal entities — a deliberate identity-fragmentation strategy that keeps each certificate clean while a shared packing toolchain quietly links the clusters behind the scenes.

    #VoidArachne#SilverFox#DigiCertcode-signingabuse#PubNubRAT#certificatefragmentation#ChinaMobileinfrastructure#trojanisedutilitysoftware#C2camouflage
    ActorsVoid Arachne · Silver FoxIOCf11 · i2 · d5 · u4MITRE4
  • FILEMembersMay 31, 2026, 21:00 (UTC+9)

    APT28 Deploys 11-Year-Old Signed Kernel Driver in Layered Credential-Theft Campaign

    A financially themed ZIP archive named HSBC_PAYMENT_ADVICE0293845678.zip is circulating as the opening move in a layered attack chain that deploys a signed vulnerable kernel driver first seen in 2015 alongside a freshly compiled DLL sideloading payload and an AgentTesla infostealer equipped with active sandbox-evasion logic.

    #APT28#AgentTesla#BYOVD#xkpsm.sys#DLLsideloading#financialsector#credentialtheft#kerneldriverabuse
    ActorsAPT28 · StrontiumIOCf43 · i0 · d0 · u0MITRE27RegionsAE · AT · AU · BDIndustriesConstruction · Engineering · Financial Services
  • APTMembersMay 31, 2026, 19:32 (UTC+9)

    Valid DigiCert Cert Turns 2345 SafeCenter Update Channel Into Malware Pipeline

    Seventeen Windows PE files masquerading as components of the 2345 SafeCenter security suite and HaoZip archiver are circulating with a currently-valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd. — a credential that suppresses Windows SmartScreen warnings and causes automated sandbox platforms to return clean verdicts on samples that 25 to 38 static antivirus engines simultaneously flag as adware.

    #SaltySpider#ad2345#Chinad#code-signingabuse#SQLServerauthenticationbypass#CDN-hostedpayloaddelivery#sandboxevasion#China
    ActorsAPT28 · StrontiumIOCf17 · i41 · d1 · u2MITRE8
  • FILEMembersMay 31, 2026, 18:27 (UTC+9)

    Trojanised BitComet Campaign Engineers 33-Engine Detection Gap via Shared Certificate

    ##A Certificate Hiding in Plain Sight: How a Trojanised BitComet Campaign Engineers Its Own Detection Gap Five Windows executables. Two code-signing identities. One AWS CloudFront subdomain. And a payload chain carefully tuned so that the component most likely to reach an endpoint registers a detection rate of just 2 out of 76 antivirus engines — while its outer wrapper, signed by the same certificate, flags on 35. That arithmetic is not an accident.

    #DealPly#OfferCore#code-signingabuse#CDNfronting#sandboxevasion#adware#financialservices#CloudFront
    IOCf58 · i4 · d1 · u0MITRE4RegionsAD · AE · AL · ARIndustriesArts & Entertainment · Education & Research · Financial Services
  • FILEMembersMay 31, 2026, 18:12 (UTC+9)

    Conduit-Signed Adware Dropper Achieved 6/54 Detections With Stomped Timestamps and C2 Victim Profiling

    A 1.28 MB Windows executable signed with a then-valid Conduit Ltd. code-signing certificate achieved just 6 of 54 possible antivirus detections while concealing a compressed multi-payload bundle in a resource section registering entropy of 8.0 — the maximum possible for a randomly distributed byte stream. That single file, the entry point for a vigram-family adware campaign targeting technology-sector users in Spain, illustrates a layered evasion architecture that goes well beyond commodity…

    #vigram#adware#code-signingabuse#browserhelperobject#PEtimestampstomping#Spain#technologysector#C2victimprofiling
    IOCf17 · i1 · d1 · u2MITRE22RegionsESIndustriesTechnology
  • C&CMembersMay 31, 2026, 18:00 (UTC+9)

    Ludashi Adware Operator Rotates to Third DigiCert Certificate Across Three Chinese Entities

    Since CTX Team's earlier coverage of the Ludashi/LuDaShi adware ecosystem, 26 additional signed PE files and 97 IP addresses have surfaced, and the most operationally significant development is not the volume — it is what the new files reveal about how the operator manages its code-signing infrastructure. A third DigiCert G4 code-signing certificate, issued to a third distinct Chinese legal entity, has now appeared in the campaign, completing a picture of deliberate, institutionalized identity…

    #Ludashi#code-signingabuse#certificaterotation#adware#Chinesethreatactor#C2infrastructure#DigiCert#defenseevasion
    ActorsFIN6 · Skeleton SpiderIOCf47 · i97 · d0 · u0MITRE6
  • APTMembersMay 31, 2026, 17:42 (UTC+9)

    TA505 ServHelper C2 Expands: Three DGA Domains, One Operator Fingerprint

    Four new command-and-control domains and eight associated URLs have surfaced in the ongoing ServHelper campaign tracked by CTX Team, extending a C2 infrastructure cluster whose internal consistency is striking in its operational discipline. The new additions — three algorithmically generated .xyz domains and a structurally isolated .cn outlier — carry fingerprints that converge on a single provisioning workflow: identical obfuscated WHOIS registrant tokens, uniform nameserver delegation through…

    #TA505#ServHelper#C2infrastructure#DGAdomains#RDPWrap#Let'sEncryptabuse#certificatetransparency#WHOISobfuscation
    ActorsTA505 · Hive0065IOCf16 · i1 · d4 · u8MITRE43
  • APTMembersMay 31, 2026, 17:24 (UTC+9)

    Salty Spider Hides Espionage Tool in Decade-Old Adware Bundle

    A 2.3-megabyte Windows executable bearing "iMesh Inc" copyright metadata is circulating as what appears to be a routine peer-to-peer client installer — but the binary, tracked by CTX Team as iMeshV22.exe, bundles the Cydoor and SaveNow adware families inside a delivery chain that combines PEiD and Armadillo packing, active debugger detection, and a version-check beacon that registers each new victim with encoded telemetry.

    #SaltySpider#Cydoor#SaveNow#adware#sandboxevasion#educationsector#France#trojanisedinstaller
    ActorsSalty Spider · KuKuIOCf18 · i0 · d4 · u2MITRE43RegionsFR · GB · NCIndustriesEducation & Research
  • FILEPublicMay 31, 2026, 09:27 (UTC+9)

    Plesk Default Certificate Exposes All Eight LummaStealer C2 Domains

    Eight command-and-control domains serving an active LummaStealer campaign share a single Let's Encrypt TLS certificate whose subject common name reads admiring-poincare.37-77-150-150.plesk.page — the auto-generated Plesk control-panel hostname for the raw IP address 37.77.150.150, hosted on Proton66 OOO (ASN 198953) in Russia.

    #LummaStealer#Pleskcertificatefingerprint#Proton66OOO#LOLBinimpersonation#code-signingchaingrafting#technologysectortargeting#Spain#Mexico
    IOCf18 · i1 · d9 · u17MITRE25RegionsES · MXIndustriesTechnology
  • C&CMembersMay 31, 2026, 09:10 (UTC+9)

    Signed Bright Data SDK Delivers PBot Stealer via Three-Layer Evasion Stack

    A 9.27-megabyte Windows executable, validly signed under a live DigiCert code-signing chain issued to Bright Data Ltd, is circulating as a trojanised update component placed directly inside Bright VPN and DriverHub installation directories — a delivery mechanism that exploits the grey-area status of commercial proxy-network software to suppress detection across the majority of the antivirus industry.

    #PBot#BrightDataSDK#code-signingabuse#Dotfuscatorobfuscation#CDNcertificatemasquerading#commercialservicessector#China-geolocatedinfrastructure#supplychaindelivery
    IOCf41 · i17 · d2 · u0IndustriesCommercial Services
  • C&CMembersMay 31, 2026, 08:55 (UTC+9)

    Dual DigiCert Certs Keep Ludashi Adware Invisible for 15 Months

    Sixteen Windows executables carrying valid, unrevoked DigiCert code-signing certificates issued to two distinct Chinese companies have been circulating as trojanized PC-optimization installers across a fifteen-month window — a sustained signed-binary abuse campaign that returns a clean verdict from every sandbox that examines it, even as detection ratios on the same files reach as high as 38 of 77 engines on VirusTotal.

    #Ludashi#code-signingabuse#Authenticodeevasion#adware#ChinesePUA#whnuowo.cn#DigiCertcertificateabuse#CDN-frontedC2
    ActorsTA551 · ShathakIOCf32 · i23 · d5 · u2MITRE6
  • C&CMembersMay 31, 2026, 08:41 (UTC+9)

    Upatre C2 Cluster Exploits Freshly Allocated French IP and 16-Year-Old Domain

    Since CTX Team's earlier coverage of this Upatre dropper campaign targeting US media-sector organisations, the infrastructure picture has sharpened considerably. The update adds no new file samples — the dropper payload itself remains unchanged — but surfaces one new C2 IP address, two new domains, and three confirmed URL-form beacon paths that together complete a hosting architecture the prior snapshot could only partially sketch.

    #Upatre#Waski#C2infrastructure#USmediasector#domainre-weaponisation#OrangeAS5511#droppercampaign#Let'sEncryptabuse
    IOCf3 · i1 · d2 · u3MITRE17RegionsUSIndustriesMedia
  • APTPublicMay 31, 2026, 08:29 (UTC+9)

    Single DigiCert Certificate Ties 11 Trojanized Files Across Two 2345 Product Lines

    Eleven Windows executables and DLLs, all bearing a currently valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd., have been confirmed as part of an expanding trojanized software campaign that now spans two distinct 2345 product lines — the SafeCenter security suite and the HaoZip archiving utility — across two coordinated build events separated by twenty days.

    #Shanghai2345MobileTechnology#code-signingabuse#DigiCertcertificate#SafeCenter#HaoZip#sandboxevasion#AlibabaCDN#Skip-2.0
    ActorsAPT28 · StrontiumIOCf17 · i43 · d1 · u2MITRE8
  • C&CMembersMay 31, 2026, 04:56 (UTC+9)

    Three-Layer Evasion Stack Targets Education Networks via Per-Victim Phishing URLs

    Thirteen individualised phishing URLs, each carrying a distinct base64-encoded payload that fingerprints the victim's browser before deciding whether to proceed — that is the opening move of a campaign CTX Team has been tracking against the education and research sector, built on infrastructure that layers domain-generation algorithm tagging, fast-flux DNS across eight A-records at 60-second TTLs, and a CNAME redirect through a secondary unanalysed domain, all backed by freshly provisioned…

    #spearphishing#fast-fluxDNS#browserfingerprinting#educationsector#C2infrastructure#domaingenerationalgorithm#redirectchain#credentialharvesting
    IOCf0 · i2 · d1 · u13MITRE10IndustriesEducation & Research
  • APTMembersMay 31, 2026, 04:42 (UTC+9)

    One DigiCert Certificate, 14 Malicious Binaries, 18 Months Unrevoked

    A single unrevoked DigiCert code-signing certificate — issued to the Chinese entity 成都奇鲁科技有限公司 and carrying serial number 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid from May 21, 2024 through May 20, 2027 — has been used to sign 14 distinct malicious Windows binaries deployed across at least six consumer-facing product brands over an 18-month window.

    #Ludashi#code-signingabuse#PUAadware#CDNfronting#TencentAPIGateway#telecommunications#China#SuperApp
    ActorsFIN6 · Skeleton SpiderIOCf26 · i1 · d7 · u12MITRE10IndustriesTelecommunications
  • FILEMembersMay 30, 2026, 23:44 (UTC+9)

    Gold Evergreen's Vidar Variant Hits Indonesia With Six-Layer Evasion Stack

    A 1.41-megabyte unsigned Win32 executable, packed to near-maximum entropy and fetched silently through an Internet Explorer cache path, is at the centre of a credential-theft operation targeting Windows users in Indonesia. The payload — confirmed as a Vidar stealer variant by three independent YARA rules and a Zenbox sandbox classification of MALWARE/STEALER/TROJAN/EVADER at 100% confidence — does not simply steal and exfiltrate.

    #GoldEvergreen#Vidarstealer#Arkeistealer#sandboxevasion#cryptocurrencywalletharvesting#dual-channelC2#Indonesia#credentialtheft
    ActorsGold Evergreen · Business ClubIOCf1 · i0 · d0 · u4MITRE11RegionsID
  • C&CMembersMay 30, 2026, 23:28 (UTC+9)

    Phorpiex Botnet Splits C2 Across Russian and AFRINIC Hosts to Resist Takedown

    A single 14-kilobyte Windows executable — compact enough to fit in a single memory page — is beaconing outward to two command-and-control servers that have been deliberately placed in different corners of the internet's address space. One sits inside a subnet allocated to Prospero OOO, a St. Petersburg-registered provider operating under AS200593 through RIPE NCC, and carries a short-lived Let's Encrypt certificate for the domain "ledgersinsured.com" as its TLS cover.

    #Phorpiex#botnetC2infrastructure#ProsperoOOO#AFRINIC#ransomware#Uzbekistan#TLScertificateabuse#wormpropagation
    IOCf1 · i2 · d0 · u8MITRE47RegionsUZ
  • FILEMembersMay 30, 2026, 21:27 (UTC+9)

    Patchwork Hides Kernel Driver and Crypto Miner in Pirated Game Crack

    A 496-megabyte file masquerading as a Football Manager 2024 crack is the entry point for one of the more technically layered campaigns CTX Team has recently dissected — a multi-stage operation attributed to Patchwork that bundles a Bring-Your-Own-Vulnerable-Driver kernel exploit, a cryptocurrency miner dressed as a Windows system binary, and a persistent obfuscation pipeline, all delivered through the oldest social-engineering lure in the book: pirated software.

    #Patchwork#BYOVD#WinRing0x64#XMRig#AutoIT#cryptocurrencymining#telecomsector#kernelexploitation
    ActorsPatchwork · ChinastratsIOCf16 · i0 · d0 · u0MITRE41RegionsAU · BR · CM · ITIndustriesTelecommunications
  • FILEMembersMay 30, 2026, 21:15 (UTC+9)

    Fake Adobe Plugin Delivers Lumma Stealer and Cryptominer via Four-Layer Chain

    A single typosquat domain — adobe-plugin.info — sits at the front of a payload chain that is considerably more engineered than its lure suggests. Behind the Adobe branding lies a structured, automated build pipeline producing at least four distinct malware components: a GCleaner MSIL trojan, a PEiD-packed dropper variant, a compact Nitol persistence stub, and a dual-purpose monetisation stage that runs Lumma stealer and a cryptominer simultaneously on the same compromised host.

    #BlueBottle#Lummastealer#CoinMiner03#Nitol#GCleaner#typosquatting#creativeandmediasector#ZIPdropper
    ActorsBlueBottle · Opera1erIOCf13 · i0 · d1 · u1RegionsUS
  • APTMembersMay 30, 2026, 20:24 (UTC+9)

    Sims 4 Crack Lure Delivers CyberGate RAT Across Nine Countries

    Three Windows executables dressed as Sims 4 crack installers and updaters are circulating across nine countries, carrying a CyberGate/Rebhip remote access trojan beneath a multi-layer evasion stack that combines NSIS dropper wrapping, active sandbox product-ID detection, and XOR-obfuscated PE stubs — a tradecraft combination deliberately engineered to defeat automated analysis pipelines before a human analyst ever sees the payload.

    #Snowglobe#CyberGate#Rebhip#NSISdropper#sandboxevasion#educationsector#telecommunications#DDNSinfrastructure
    ActorsSnowglobe · Animal FarmIOCf10 · i0 · d1 · u1MITRE41RegionsBE · LT · PL · RSIndustriesEducation & Research · Telecommunications
  • FILEMembersMay 30, 2026, 17:21 (UTC+9)

    XWorm RAT Hides C2 Behind Three Evasion Gates in RFQ Phishing Wave

    A pair of Windows executables disguised as purchase-order documents began circulating on 7 May 2026, carrying a commodity remote-access trojan wrapped in enough evasion machinery to slip past automated analysis pipelines and arrive on victim systems with its command-and-control address still largely unknown to the industry. The campaign — tracked by CTX Team under the identifier CTXk3fv3k5gux — delivers XWorm RAT via a ZIP archive whose sole contents are a batch script named to mimic a…

    #XWorm#SpyEx#procurementphishing#sandboxevasion#ip-api.comhosting-providercheck#energysector#manufacturingsector#commodityRAT
    IOCf4 · i1 · d0 · u1MITRE40RegionsAL · AU · BD · CAIndustriesEnergy · Manufacturing · Retail
  • FILEMembersMay 30, 2026, 11:53 (UTC+9)

    Signed LummaStealer Bundle Clears 76 AV Engines With DigiCert Certificate

    Five Windows executables carrying a valid, unexpired Reason Cybersecurity Inc. code-signing certificate — all signed in a single session at 08:53 AM on May 26, 2026, under DigiCert Trusted G4 certificate serial 07 8A A6 13 E0 E5 D5 AB 31 96 67 B9 3D 2B 96 73 — have been circulating as the payload core of a LummaStealer distribution campaign that achieves zero detections across 76 antivirus engines. The delivery vehicle is a trojanised uTorrent installer signed by BitTorrent Inc.

    #LummaStealer#code-signingabuse#certificateevasion#uTorrentlure#CDNmasquerade#credentialtheft#scheduledtaskpersistence#DigiCert
    IOCf67 · i4 · d1 · u0MITRE49RegionsAE · AR · AT · AUIndustriesConsulting · Education & Research · Telecommunications
  • APTMembersMay 30, 2026, 10:44 (UTC+9)

    Chrome-Impersonating Mach-O Binaries Hit Government Macs With 0/76 AV Detections

    Two universal Mach-O binaries impersonating Google Chrome — signed with a valid Apple Developer-issued certificate bearing the Google LLC identity, yet carrying a MissingPlist code-signing verdict that defeats Gatekeeper's full bundle validation — are circulating against government-sector macOS targets with zero detections across 76 antivirus engines.

    #Cactus#MissingPlist#macOS#governmentsector#signedbinaryabuse#DNS-over-HTTPS#Chromeimpersonation#Mach-O
    ActorsCactus · Cactus Ransomware GroupIOCf2 · i2 · d4 · u4MITRE5IndustriesGovernment
  • FILEMembersMay 30, 2026, 07:30 (UTC+9)

    Pay-Per-Install Campaign Adds CryptOne Dropper and Two C2 Domains in Nine Days

    Since CTX Team's earlier coverage of this pay-per-install operation, the campaign has added ten new file indicators, stood up two freshly provisioned command-and-control domains within nine days of each other in May 2026, and introduced a raw-IP payload-delivery endpoint on a Netherlands-based host whose TLS certificate presents a deliberately misleading identity.

    #pay-per-install#CryptOne#Microleavesadware#ORYONTECHLIMITED#OmegatechLTD#EVcertificateabuse#fakecrackedsoftware#NetherlandsC2infrastructure
    IOCf23 · i1 · d3 · u6MITRE31RegionsBR · EG · GB · PLIndustriesTechnology
  • C&CMembersMay 30, 2026, 07:04 (UTC+9)

    Trojanised VPN Installer Weaponises Two Legitimate Code-Signing Chains

    A 14.5-megabyte NSIS self-extracting archive named WireVpn_v3.6.0.3-6872e76.exe has been circulating through a curated software-distribution channel labelled "TS Recommended Apps" — bearing a valid Extended Validation code-signing certificate from GlobalSign, issued to a Chinese-registered entity called WEILAI NETWORK TECHNOLOGY CO., LIMITED, and dropping kernel-level netfilter drivers alongside proxy and jumper binaries that collectively form an espionage-oriented command-and-control platform.

    #WireVPN#PBot#WEILAINETWORKTECHNOLOGY#BrightDataSDK#code-signingabuse#netfilterkerneldriver#signedbinaryproxyexecution#credentialstealer
    ActorsSprite Spider · Gold DupontIOCf27 · i27 · d94 · u12MITRE24
  • APTMembersMay 30, 2026, 06:22 (UTC+9)

    One Code-Signing Cert, 15 Malware Families, Valid Until 2027

    A single DigiCert code-signing certificate issued to a Chinese commercial entity has been used to sign 15 distinct malicious PE32 executables spanning six threat families over a twelve-month window — and it remains valid through May 2027. The certificate, issued to 成都奇鲁科技有限公司 (serial 0D078E70EAEE48FFEB9576BDD400BE98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0), has functioned as a persistent OS-level trust bypass [T1553.002] across the entire payload portfolio, enabling malicious…

    #SaltySpider#Ludashi#Chinad#Doina#code-signingabuse#ChinesePUAecosystem#signedbinaryproxyexecution#certificaterevocationgap
    ActorsGroup123 · Venus 121IOCf23 · i5 · d2 · u0MITRE16
  • FILEMembersMay 30, 2026, 01:34 (UTC+9)

    Frozen RAT Builder, Free DNS Alias Keep klovbot Active Since 2017

    Sixteen Windows PE32 executables tied to the klovbot malware family are circulating against technology-sector targets in Moldova, and the most operationally revealing detail about the campaign is not the payload — it is the degree to which the operator has changed almost nothing since at least 2017. Three of those files carry enough metadata for deep analysis, and what that analysis surfaces is a tradecraft combination that has outlasted most of the defensive signatures written against it: an…

    #klovbot#DarkKomet#XRed#dynamicDNS#Moldova#technologysector#sandboxevasion#USBspreader
    IOCf16 · i1 · d0 · u0MITRE24RegionsMDIndustriesTechnology
  • C&CMembersMay 30, 2026, 00:50 (UTC+9)

    Sequential C2 Panel Paths Expose Seychelles-Registered Bulletproof Hosting Behind Spain Infostealer Campaign

    Three new command-and-control IP addresses have surfaced in the latest observation window of a SmokeLoader and Rhadamanthys infostealer campaign targeting victims in Spain — and the way those addresses were provisioned tells a more precise story than the malware families themselves. Two of the IPs share a single autonomous system number, AS202412, registered to Omegatech LTD, a Seychelles-incorporated entity whose RIPE NCC address block allocations were created within a single month of each…

    #SmokeLoader#Rhadamanthys#bulletproofhosting#credentialtheft#Spain#cryptocurrencywallettheft#C2infrastructure#infostealer
    ActorsAPT28 · StrontiumIOCf34 · i3 · d0 · u4MITRE49RegionsES
  • APTMembersMay 30, 2026, 00:33 (UTC+9)

    SmokeLoader Campaign Adds Trojanized Card-Checker Lure, Third C2 Node

    Since CTX Team's earlier coverage of this SmokeLoader-driven infostealer operation, seven new file indicators have surfaced alongside a full refresh of the campaign's three command-and-control IPs — and the most significant development is not the infrastructure update but what it reveals about how the operator is now getting onto victim machines.

    #SmokeLoader#trojan.marsilia#APT39#infostealer#bulletproofhosting#Spain#cryptocurrencytheft#logmarketplace
    ActorsAPT39 · ChaferIOCf35 · i3 · d0 · u5MITRE48RegionsES
  • C&CMembersMay 29, 2026, 20:56 (UTC+9)

    Six-Year-Old Phorpiex Dropper Hits Kazakhstan on Fresh Romanian VPS

    A 412-kilobyte Windows executable — unsigned, packed, and masquerading as a tape-toolbar utility from the year 2000 — has been actively beaconing to a freshly provisioned Romanian virtual private server since at least March 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan.

    #Phorpiex#ClipBanker#USBworm#Kazakhstan#educationsector#governmentsector#clipboardhijacking#commoditybotnet
    IOCf8 · i1 · d0 · u10MITRE36RegionsKZIndustriesEducation & Research · Government
  • APTMembersMay 29, 2026, 19:27 (UTC+9)

    Two Shell Companies, Two DigiCert Certs, One Ludashi Campaign

    Twenty Windows executables and DLLs carrying currently-valid DigiCert code-signing certificates are circulating across telecom-sector endpoints, each one disguised as a routine Windows system utility — a PC cleaner, a BSOD repair tool, a browser protection suite — and each one backed by a C2 cluster that routes through China Unicom's backbone while presenting financial-services TLS cover.

    #FIN6#TA428#lockergoga#ncctrojan#lummastealer#Telecommunications
    ActorsFIN6 · Skeleton SpiderIOCf29 · i2 · d4 · u4MITRE6IndustriesTelecommunications
  • APTMembersMay 29, 2026, 18:20 (UTC+9)

    Revoked Certum Cert Evades 75 of 76 Engines in Ludashi Adware Pivot

    Two freshly minted Windows executables, both signed by a previously unseen Chinese entity called 深圳市禹仁科技有限公司 and both carrying a Certum code-signing certificate that had already been revoked at the time of deployment, surfaced on VirusTotal on 23 May 2026 — just six days before CTX Team's analysis. One of the two files, a 346-kilobyte PE32 executable installed under C:\Program Files (x86)\ProZip\Bin\nhlj32.exe, was flagged by exactly one of 76 scanning engines.

    #FIN6#SaltySpider#lockergoga#lummastealer#sality
    ActorsFIN6 · Skeleton SpiderIOCf26 · i11 · d10 · u8MITRE16
  • APTMembersMay 29, 2026, 17:53 (UTC+9)

    Four Shell Companies, One CA: How Ludashi Buries Payloads in Trusted Certs

    Seventeen Windows executables and DLLs. Four distinct Chinese corporate identities. A single DigiCert intermediate certificate authority threading through all of them. That is the structural core of a Ludashi adware and trojan campaign that CTX Team has been tracking across a ten-month payload timeline stretching from July 2025 through late May 2026 — a campaign that uses rotating shell-company code-signing certificates, deliberate PE header corruption, and a pre-staged CDN infrastructure built…

    #Patchwork
    ActorsPatchwork · ChinastratsIOCf20 · i8 · d10 · u52MITRE18
  • FILEMembersMay 29, 2026, 14:42 (UTC+9)

    Single Sectigo EV Certificate Signs Four Malicious Payloads in One Batch

    Four malicious Windows executables — spanning PE32, PE32+, and MSI formats, collectively masquerading as a legitimate system utility suite called "Advanced Windows Manager" — were signed with a single valid Sectigo Extended Validation code-signing certificate in one batch event on the morning of 23 April 2026. The certificate, issued to an entity named "ORYON TECH LIMITED" under the Sectigo Public Code Signing CA EV R36 chain (serial 21 E3 D5 C7 00 22 7E A0 2E E6 84 AF 4F 8F 88 40, thumbprint…

    #ORYONTECHLIMITED#GCleaner#EvilCh/CryptOne#pay-per-install#EVcertificateabuse#code-signing#Egypt#UnitedKingdom
    IOCf23 · i1 · d3 · u7MITRE48RegionsEG · GBIndustriesTechnology
  • C&CMembersMay 29, 2026, 14:28 (UTC+9)

    PBot Stealer Gets 64-Bit Rebuild, Drops to 9/76 Detections

    Since CTX Team's earlier coverage of this VPN-lure PBot stealer campaign, the most operationally significant development is not the expansion of the domain or IP set — though both have grown substantially — but a single freshly compiled binary that signals the operator is actively retooling the payload build pipeline rather than coasting on existing artifacts.

    #ramnit#beacon
    IOCf9 · i28 · d51 · u6MITRE23
  • APTMembersMay 29, 2026, 10:16 (UTC+9)

    Ludashi Campaign Expands C2 Layer With Cloud Proxy Evasion

    Since CTX Team's earlier coverage of this campaign, the observable payload set has contracted while the network infrastructure has expanded dramatically — 21 new IP addresses, six new C2 domains, and seven new URLs have entered the picture, with zero new file payloads added. The delta is entirely in the network layer, and what it reveals is a meaningful escalation in how the operators route and obscure their command-and-control traffic.

    #TA551#icedid
    ActorsTA551 · ShathakIOCf19 · i21 · d6 · u7MITRE12
  • APTMembersMay 29, 2026, 10:04 (UTC+9)

    Emotet Revives 18-Year-Old Domains in Coordinated Chile Campaign

    Three .com domains registered between November 2007 and January 2008 — old enough to predate the iPhone's first software update cycle — have been quietly reactivated as payload-staging and command-and-control nodes for an Emotet-linked campaign targeting Chile. The reactivation was not gradual. Between 17 April and 4 May 2026, all three domains received fresh 89-day Let's Encrypt certificates within a compressed 17-day window, a coordinated provisioning pass that CTX Team's analysis identifies…

    #EmotetGroup#emotet
    ActorsEmotet Group · TA542IOCf3 · i2 · d3 · u6RegionsCL
  • APTMembersMay 29, 2026, 09:53 (UTC+9)

    Trojanised Dr.Fone Installer Delivers VjW0rm via Three-Continent CDN-Masquerade C2

    Nine new file indicators and one additional command-and-control IP have been added to the TA2541-linked VjW0rm cluster since earlier coverage, expanding a campaign whose most operationally distinctive feature was never the payload itself but the infrastructure architecture surrounding it: three geographically dispersed servers, each presenting a wildcard-SAN TLS certificate impersonating a different major CDN brand, observed within a 48-hour window and spread across three separate autonomous…

    #TA2541#VjW0rm#CDNimpersonation#NSISdropper#JavaScriptworm#C2infrastructure#EgyptFranceRomaniaUnitedStates#OperationLayover
    ActorsTA2541 · Operation LayoverIOCf17 · i3 · d1 · u2RegionsEG · FR · RO · US
11
Of13
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.