FILEMembersMay 29, 2026, 06:45 (UTC+9)One .NET Builder, Two Malware Families, One Turkish C2 IP
A single PE import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the forensic thread that ties together what initially appears to be two separate commodity malware campaigns. On one end sits a 239-kilobyte AgentTesla infostealer, first submitted to VirusTotal in December 2025 and confirmed malicious by all three sandboxes that analysed it.
#agenttesla#HospitalityLeisure#TechnologyIOCf21 · i1 · d0 · u1MITRE41RegionsMA · TRIndustriesHospitality & Leisure · Technology
APTMembersMay 29, 2026, 05:53 (UTC+9)One Unrevoked Certificate, 18 Builds: Inside a 14-Month Adware Campaign
A DigiCert code-signing certificate issued to a Chengdu technology company has been used continuously for more than 14 months to sign trojanized Windows executables masquerading as components of LuDaShi (鲁大师), one of China's most widely installed PC-optimization suites — and that certificate remains unrevoked today. CTX Team's latest sweep of the campaign has surfaced 41 new file indicators alongside a purpose-built command-and-control domain pair registered in December 2025 that carries a 0/91…
#FIN6#TA428#Group123#lockergoga#ncctrojan#lummastealerActorsFIN6 · Skeleton SpiderIOCf60 · i27 · d4 · u1MITRE13
FILEMembersMay 29, 2026, 02:45 (UTC+9)Packed .NET Stealer Hits Healthcare in 7 Countries With Sandbox-Aware Evasion
A 593-kilobyte .NET assembly, unsigned and unremarkable in appearance, has been circulating against healthcare organisations across Belgium, India, Italy, Sri Lanka, Pakistan, Tunisia, and the United States since at least March 2026. What makes it analytically interesting is not its payload — credential theft is commodity work — but the layered effort its operators invested in making sure analysts never get a clean look at it.
#HealthcareIOCf3 · i1 · d0 · u1MITRE24RegionsBE · IN · IT · LKIndustriesHealthcare
APTMembersMay 29, 2026, 01:53 (UTC+9)Three DigiCert Certs, One Builder: Inside a Chinese Adware Signing Pipeline
Somewhere between a disk-cleaner utility and a remote-access implant, a modular Windows toolkit has been quietly circulating across Chinese software distribution channels, its every component bearing a valid DigiCert code-signing certificate issued to a registered Chinese legal entity. The campaign — tracked by CTX Team across at least 41 PE32 files and 20 confirmed network endpoints — deploys under four consumer-software personas (DupsClean, LargeFileClean, BirdWallpaper, and BlueDoveUnist)…
#APT33#shapeshift#icedidActorsAPT33 · MagnalliumIOCf41 · i77 · d3 · u2MITRE15
FILEMembersMay 28, 2026, 23:13 (UTC+9)Amadey Loader Hits Academic Networks Across 11 Countries via IE5 Cache
A freshly submitted Win32 executable — unsigned, just over 2 MB, first observed on VirusTotal on 2026-05-07 — is delivering a credential-harvesting payload to education and research institutions across eleven countries, using a staging chain that exploits legacy Internet Explorer cache paths, embeds a secondary payload in the binary's overlay section, and beacons home over raw HTTP to a single IPv4 address on a Seychelles-registered autonomous system that was provisioned less than nine months…
#APT28#EducationResearchActorsAPT28 · StrontiumIOCf2 · i1 · d0 · u1MITRE25RegionsBA · BO · CO · INIndustriesEducation & Research
FILEMembersMay 28, 2026, 22:59 (UTC+9)Expired 2017 Certificate Still Powers Process Hacker 2 Offensive Toolkit
Seventeen Windows executables — two main GUI binaries, a kernel-mode driver, a PE viewer, and thirteen plugin DLLs — have been assembled into a unified offensive package and are circulating with Authenticode signatures that expired in January 2017. The signing identity is "Wen Jia Liu," issued under two DigiCert certificate serials that together bind every file in the toolkit to a single developer lineage.
#RoyalRansomware#CommentCrew#glasses#prochackActorsRoyal Ransomware · Team OneIOCf19 · i0 · d0 · u0MITRE10
C&CMembersMay 28, 2026, 22:40 (UTC+9)Trojanized Security Suite Uses Valid DigiCert Cert to Blind Sandboxes
Nine PE32 components masquerading as a legitimate Chinese consumer security product are circulating with a currently-valid DigiCert code-signing certificate, a direct-syscall evasion technique confirmed by YARA, and payload delivery routed through Alibaba's KunlunCan CDN — a combination that collapses sandbox verdicts to zero while roughly half of antivirus engines still flag the files on static analysis alone. The gap between those two numbers is the operational story of this campaign.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf9 · i21 · d2 · u5MITRE22
C&CMembersMay 28, 2026, 22:28 (UTC+9)One DigiCert Cert, 14 Executables, Nine Months Undetected
Fourteen distinct Windows executables. Six different product personas. One code-signing certificate — and nine months of continuous, largely undetected operation. That is the operational picture CTX Team has assembled from a cluster of signed PE32 binaries circulating through the Ludashi PUA distribution ecosystem, all stamped with a single DigiCert certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid through 2027-05-20).
#FIN6#Group123#SaltySpider#lockergoga#salityActorsFIN6 · Skeleton SpiderIOCf23 · i25 · d4 · u1MITRE11
APTMembersMay 28, 2026, 21:56 (UTC+9)Dual DigiCert Certs Cloak Adware-to-RAT Campaign Across 19 Payloads
##A Single Certificate, Nineteen Signed Payloads, and a RAT Hidden Inside an Adware Framework Nineteen Windows binaries carrying valid DigiCert code-signing certificates — issued to two distinct Chinese-registered entities — have been circulating across Mandarin-language software distribution channels for at least eight months, wrapping a Ludashi/PolarWind adware framework around a RAT-capable core that most endpoint products still cannot see clearly.
#FIN6#TA428#APT23#lockergoga#ncctrojan#lummastealerActorsFIN6 · Skeleton SpiderIOCf61 · i5 · d3 · u3MITRE20
FILEMembersMay 28, 2026, 19:00 (UTC+9)Fake Windows DLL Targets Singapore Construction Firms in 16-Year Campaign
A 43-kilobyte Windows DLL masquerading as the operating system's own language-pack library is at the centre of an active implant chain targeting Singapore's construction sector — a toolkit that combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence into a layered evasion architecture that has remained operationally relevant from its first recorded submission in July 2010 through at least May 2026.
#GoblinPanda#avzhan#ConstructionActorsGoblin Panda · CycldekIOCf2 · i0 · d0 · u0MITRE23RegionsSGIndustriesConstruction
FILEMembersMay 28, 2026, 18:49 (UTC+9)Signed VPN Installer Trojan Targets Food and Beverage Firms
Three Windows executables — VPNMaster.exe, Startup.exe, and master_vpn-service.exe — are circulating as components of a coherent VPN product installation, each carrying a DigiCert G4 code-signing certificate issued to a Singapore-registered entity called "INNOVATIVE CONNECTING PTE. LIMITED." The certificate, serial number 0C 8F 89 21 C5 36 49 3E 67 DF 84 FB 82 23 B0 92, expired on 2 April 2026, yet the binaries remain structurally signed and continue to bypass security controls on systems that…
#Barium#APT15#Cactus#ramnit#FoodBeveragesActorsBarium · Wicked SpiderIOCf14 · i1 · d6 · u1MITRE7IndustriesFood & Beverages
C&CMembersMay 28, 2026, 18:31 (UTC+9)One EV Certificate, Two Trojans, Three Fake Windows Binaries
Two trojan.jumper payloads circulating under the guise of a WireVPN client share an identical GlobalSign Extended Validation code-signing certificate — serial 03 A9 18 8A A5 10 C0 F8 34 34 26 BF, issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED — while three companion files masquerade as canonical Windows system executables, carrying valid Microsoft signatures and zero detections across 76 scanning engines.
#beacon#AutomotiveIOCf6 · i6 · d6 · u0MITRE12IndustriesAutomotive
C&CMembersMay 28, 2026, 18:11 (UTC+9)Space Pirates Add Signed .NET Stealer to Trojanized-VPN Arsenal
Since CTX Team's earlier coverage of this campaign, eight new malicious files and a complete refresh of 18 IP addresses and 26 domains have surfaced — but the most operationally significant development is not the scale of the infrastructure turnover. It is the addition of a third signed-binary abuse vector: a Dotfuscator-packed, encrypted .NET stealer classified as PBot, hidden inside a binary carrying a valid Bright Data Ltd code-signing certificate.
#SpacePirates#ramnit#beaconActorsSpace Pirates · WebwormIOCf14 · i18 · d26 · u4MITRE17
FILEMembersMay 28, 2026, 14:45 (UTC+9)APT28's Three-Signer Chain Leaves Four Files at Zero Detections
Eight Windows executables. Three separate trusted signing identities. Four files sitting at zero detections across 76 antivirus engines. The campaign that CTX Team has been tracking under the RostPay/RostDown family designation is not a blunt-force intrusion operation — it is a methodical exercise in trust subversion, engineered so that the failure of any single certificate or detection rule leaves at least two other evasion layers intact.
#APT28#nitol#ghost#CommercialActorsAPT28 · StrontiumIOCf8 · i2 · d0 · u0MITRE11IndustriesCommercial Services
FILEMembersMay 28, 2026, 10:58 (UTC+9)XWorm Campaign Expands to Three-Channel C2 Fabric Across Offshore ASNs
Since CTX Team's earlier coverage of this XWorm campaign, two freshly provisioned command-and-control nodes have surfaced in RIPE NCC address space allocated in late 2025 — 158.94.209.22 under ASN 202412 (Omegatech LTD, Seychelles-registered) and 143.20.134.59 under ASN 215703 (Freakhosting Ltd, nominally UK-registered) — alongside a new dynamic DNS endpoint, jar5.ydns.eu, that carries no VirusTotal detection data at all.
#Commercial#Government#Manufacturing#Media#SupportServiceActivities#TechnologyIOCf12 · i2 · d0 · u1MITRE33RegionsAT · BE · BS · CAIndustriesCommercial Services · Government · Manufacturing
C&CMembersMay 28, 2026, 06:11 (UTC+9)Ludashi PUA Pivots to Cloud-Fronted C2 via Tencent API Gateway
Since CTX Team's earlier coverage of the Ludashi PUA campaign, the observable infrastructure has undergone a complete turnover: twelve new IP addresses, six new domains, and seven new URLs have entered the active indicator set, while every previously tracked file has rotated out. The payload layer is quiet — zero new binaries — but the network layer tells a story of deliberate, operationally sophisticated infrastructure replacement.
#TA551#icedidActorsTA551 · ShathakIOCf19 · i12 · d6 · u7MITRE12
APTMembersMay 28, 2026, 05:53 (UTC+9)Signed DLL in Adware Chain Confirmed as PubNubRAT
For eighteen months, a campaign built around two DigiCert code-signing certificates issued to Chengdu-registered entities moved through Chinese-language Windows environments largely beneath the noise floor — its payloads labelled adware, its delivery mechanism a well-known PC-utility ecosystem, its detection rates low enough that signed binaries slipped past Windows SmartScreen with detection ratios as low as 10 of 77 engines. That picture changed with the appearance of a single DLL.
#APT23#lummastealerActorsAPT23 · KeyBoyIOCf28 · i26 · d2 · u3MITRE13
FILEMembersMay 28, 2026, 02:47 (UTC+9)KMSpico Trojan Chain Delivers LummaStealer to Kenya's Tech Sector
Four Windows executables carrying the same self-issued code-signing certificate have been circulating as KMSpico software activators for nearly a decade — and CTX Team's analysis of a recently surfaced indicator cluster shows that the same @ByELDI Certificate Authority, serial number CB C9 53 5C 7A 4B 70 DE 52 6C 01 39 FE AF 2C 9C, still binds the distribution chain today.
#LazarusGroup#lummastealer#TechnologyActorsLazarus Group · Hastati GroupIOCf17 · i1 · d0 · u0MITRE42RegionsKEIndustriesTechnology
FILEPublicMay 28, 2026, 02:32 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Telecom Cryptomining Campaign
Compiled on April 16, 2026, and submitted to VirusTotal just two days later, an unsigned 2.5-megabyte Windows executable is doing something that should give pause to every security team protecting telecommunications infrastructure: it is loading a kernel driver that was signed in 2008, whose Authenticode certificate expired that same year, and whose vulnerabilities have been publicly catalogued for years — and using that driver to claw its way to ring-zero privilege before beaconing out to a…
#LazarusGroup#BYOVD#WinRing0x64#cryptomining#telecommunications#LOLDrivers#privilegeescalation#HashVaultActorsLazarus Group · Hastati GroupIOCf4 · i1 · d0 · u0MITRE31RegionsAR · BG · BR · GRIndustriesTelecommunications
C&CMembersMay 28, 2026, 02:13 (UTC+9)Fake Speed-Test Utility Hides Eight-Year C2 Network With *.malware.com Cert
Two subdomains. One IP address. One self-signed TLS certificate whose common name is literally *.malware.com. The infrastructure behind a shlayer-attributed potentially unwanted program (PUP) campaign targeting the energy sector is not subtle — but its longevity is. The parent domain buffernavpose.com was registered on 2018-05-12 via Dynadot Inc, has been actively maintained through at least April 2026, and carries a certificate valid until 2030-05-11.
#shlayer#EnergyIOCf2 · i0 · d2 · u10MITRE15IndustriesEnergy
APTMembersMay 28, 2026, 01:59 (UTC+9)Ludashi Campaign Adds 13 Payloads, Tencent CDN Relay to Evasion Stack
Thirteen new Windows PE32 binaries signed under a single DigiCert code-signing certificate have entered the Ludashi-ecosystem campaign since CTX Team's prior coverage, while a freshly provisioned four-subdomain C2 cluster under tjbxldkj.cn and a Tencent Cloud API Gateway domain-fronting relay on ss.dllfix.cn represent infrastructure capabilities that were absent from the earlier operation.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf32 · i23 · d6 · u8MITRE12
C&CMembersMay 27, 2026, 21:54 (UTC+9)Six-Year-Old Batch Script Powers 2025 Telecom Espionage Campaign
A trojanised ZIP archive impersonating the legitimate Microsoft Activation Scripts open-source project is circulating across enterprise endpoints, embedding active sandbox-evasion logic inside what victims perceive as a trusted Windows activation utility — and funnelling compromised hosts toward a freshly constructed, deliberately compartmentalised command-and-control infrastructure spanning three distinct autonomous systems with no cross-node certificate or DNS linkage between them.
#TA505#Cactus#goldeneye#TelecommunicationsActorsTA505 · Hive0065IOCf2 · i2 · d1 · u17MITRE4IndustriesTelecommunications
C&CMembersMay 27, 2026, 18:11 (UTC+9)WireVPN Campaign Adds 132 Domains and a PBot Stealer Component
Fifty-five new command-and-control IPs and 132 additional domains have joined the Trojan.Jumper/WireVPN campaign's observable footprint since CTX Team's earlier coverage, transforming what was a 15-domain, 9-ASN operation into a multi-continent hosting fabric organised across five named fingerprint clusters. The expansion is not random: every cluster is bound by a shared certificate issuer, autonomous system, or registrar identity, and the core payload chain — three PE32 executables all signed…
#SpacePirates#CactusActorsSpace Pirates · WebwormIOCf4 · i55 · d132 · u19MITRE14
C&CMembersMay 27, 2026, 17:56 (UTC+9)Salty Spider Expands to Dual-Domain C2 With UnionPay TLS Fingerprint
Nine command-and-control domains, nine documented URL paths, and 31 IP addresses — none present in prior coverage — have surfaced in the latest observed activity tied to the Salty Spider campaign, exposing for the first time the full operational infrastructure behind a signed-binary adware toolkit that CTX Team has been tracking across multiple observation windows.
#SaltySpider#lummastealer#salityActorsSalty Spider · KuKuIOCf51 · i31 · d9 · u9MITRE8
C&CMembersMay 27, 2026, 13:52 (UTC+9)Trojan.Jumper Builds Five-Tier C2 Across 15 Domains and 9 ASNs
Fifteen new domains. Nine IP addresses spanning six autonomous systems across four continents. Five distinct certificate-issuer fingerprints provisioned within a 45-day window. Since CTX Team's earlier coverage of the Trojan.Jumper campaign, the operator has not merely maintained an existing footprint — they have constructed a layered, multi-tier command-and-control architecture that reveals a level of infrastructure investment inconsistent with opportunistic or low-sophistication adversaries.
#GovernmentIOCf4 · i9 · d15 · u4MITRE18IndustriesGovernment
FILEMembersMay 27, 2026, 10:29 (UTC+9)One Imphash, Two Malware Families: Inside a Shared .NET Builder
A purchase-order-themed spear-phishing campaign active since mid-May 2026 has delivered something more operationally revealing than its commodity tooling alone would suggest: two functionally distinct malware families — XWorm RAT and AgentTesla infostealer — sharing an identical PE import-table hash (imphash f34d5f2d4577ed6d9ceec516c1f5a744) and the same PEiD packer signature, confirming both were produced by a single .NET builder kit or shared loader stub.
#agenttesla#Automotive#Commercial#Construction#EducationResearch#EnergyIOCf9 · i1 · d0 · u1MITRE53RegionsAT · AU · BD · BEIndustriesAutomotive · Commercial Services · Construction
FILEPublicMay 27, 2026, 06:47 (UTC+9)Gamaredon Hides Credential-Stealer in Trojanized Driver Utility
A 39-megabyte Windows installer masquerading as the legitimate Easeware DriverEasy driver-update utility is circulating with a forged compile timestamp, a near-maximum-entropy resource section concealing an encrypted payload, and two Dotfuscator-obfuscated .NET implant components built in the same toolchain session — a layered evasion architecture that CTX Team has attributed to Gamaredon Group and linked to construction-sector targeting.
#GamaredonGroup#gamaredon#ConstructionActorsGamaredon Group · CTIGIOCf4 · i0 · d0 · u0MITRE27IndustriesConstruction
APTMembersMay 27, 2026, 06:02 (UTC+9)Trojanised Office Tool Hides Multi-Stage Intrusion Behind Streaming C2
A trojanised version of OfficeRTool — a popular Microsoft Office removal and activation utility distributed through piracy channels — is serving as the entry point for a disciplined, multi-phase intrusion operation that layers sandbox-evading VBScript components, a vhash-identical PowerShell downloader maintained across at least six major tool versions, expired-certificate network reconnaissance, and a command-and-control channel engineered to look indistinguishable from HLS media streaming…
#LockbitGang#expiro#GovernmentActorsLockbit GangIOCf7 · i3 · d2 · u8MITRE11IndustriesGovernment
APTMembersMay 27, 2026, 05:51 (UTC+9)Expired-Cert Installer Evades Sandboxes, Feeds 15-Domain Crypto Fraud Net
A 4.3-megabyte Windows installer, dressed in the branding of legitimate freeware and carrying a Sectigo-issued code-signing certificate that had already expired, is the entry point for a financially motivated campaign that routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains.
#APT28#APT15#bumblebee#EnergyActorsAPT28 · StrontiumIOCf62 · i6 · d15 · u11MITRE12IndustriesEnergy
FILEMembersMay 27, 2026, 01:21 (UTC+9)XWorm Worm Campaign Hits 24 Countries via Spanish Quotation Lure
A 914-kilobyte Windows executable masquerading as a Spanish-language purchase-order request is circulating across 24 countries, carrying a payload combination that goes well beyond what most commodity-RAT deployments attempt: XWorm and PureLog Stealer bundled together, wrapped in a PEiD-packed binary with a .text section entropy of 7.83, and equipped with a worm-propagation module that can copy the infection to removable media without any additional operator action.
#BusinessAssociations#Chemicals#Construction#Engineering#Government#ManufacturingIOCf12 · i2 · d0 · u1MITRE32RegionsAT · BE · CA · CHIndustriesBusiness Associations · Chemicals · Construction
FILEMembersMay 27, 2026, 00:53 (UTC+9)APT28 Hides Espionage Chain Inside Piracy Activation Toolkit
Seventeen files. One freshly minted domain. A Moldovan hosting provider with a near-clean reputation score. On the surface, the package looks like something millions of Windows users have downloaded without a second thought: a piracy toolkit for activating unlicensed Microsoft software. Look past the familiar filenames and the campaign reveals something considerably more deliberate — a multi-layer espionage delivery chain attributed by CTX Team to APT28, the Russian state-aligned threat actor…
#APT28#powershell#TelecommunicationsActorsAPT28 · StrontiumIOCf17 · i1 · d1 · u0MITRE15IndustriesTelecommunications
APTMembersMay 27, 2026, 00:03 (UTC+9)APT28 Splits EV Certificate and LummaC2 Stealer Across Two-Tier Chain
Four Windows executables carrying a valid Extended Validation code-signing certificate issued to an entity called ORYON TECH LIMITED are circulating as a disguised system-utility package — while a pair of freshly compiled LummaC2 stealers, deliberately stripped of any trusted certificate chain, rides the same delivery infrastructure toward the same targets. The deliberate split is not an oversight.
#APT28#gcleaner#TechnologyActorsAPT28 · StrontiumIOCf21 · i2 · d5 · u8RegionsUSIndustriesTechnology
APTMembersMay 26, 2026, 23:45 (UTC+9)Signed, Sealed, Trojanized: Dual Chengdu Certs Power RAT Campaign
Eighteen Windows PE32 files — executables and DLLs impersonating Ludashi SuperApp system utilities — are circulating with currently-valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, producing uniformly clean sandbox verdicts despite industry detection ratios that reach as high as 34 of 76 engines.
#Turla#FIN6#Group123#lockergoga#ncctrojan#xtreme_ratActorsTurla · Iron HunterIOCf57 · i27 · d7 · u1MITRE16IndustriesTelecommunications
C&CMembersMay 26, 2026, 22:40 (UTC+9)One DigiCert Cert Signed 16 Malicious Binaries Across 18 Months
Sixteen distinct Windows binaries. Eight separate product personas. One DigiCert code-signing certificate — and not a single revocation in eighteen months. That is the operational core of a sustained adware and data-harvesting campaign that CTX Team has been tracking across the Ludashi (鲁大师) software ecosystem, where malware dressed as Chinese security utilities has been circulating since at least November 2024.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf30 · i25 · d9 · u9MITRE12
APTMembersMay 26, 2026, 22:24 (UTC+9)FunkSec macOS Implant Evades 76 AV Engines via Fake Chrome Signing
Two Mach-O universal binaries named com.google.Chrome.helper — each 166 kilobytes, each signed with a structurally present but functionally invalid Google LLC code-signing certificate, each returning zero detections across all 76 antivirus engines on VirusTotal — are circulating as part of a campaign CTX Team has attributed to FunkSec, targeting engineering and government sector organisations operating macOS endpoints.
#FunkSec#Engineering#GovernmentActorsFunkSecIOCf2 · i12 · d47 · u31MITRE8IndustriesEngineering · Government
APTMembersMay 26, 2026, 22:03 (UTC+9)Salty Spider Turns Revoked Certificates Into a 71/76 Evasion Tool
Two Windows executables submitted to public malware repositories on 23 May 2026 — both signed with a code-signing certificate that had already been revoked by its issuing CA — cleared 71 of 76 scanning engines without triggering a single alert. The files, bearing the product description "Pro解压缩" (Pro Decompression) and the internal name uninst.exe, were the freshest output of a campaign that CTX Team has been tracking across a ten-month arc stretching from July 2025 to the present.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf15 · i1 · d8 · u3MITRE42
C&CMembersMay 26, 2026, 21:16 (UTC+9)AS214351 Adds 'PureCrack' Relay Node and DGA Domains in C2 Expansion
Since CTX Team's earlier coverage of this financially motivated campaign — documented then as a raw-IP beaconing operation running six malware families across a single young autonomous system — ten new files, two algorithmically generated domains, and a second command-and-control IP have surfaced. The most operationally significant addition is not another payload variant but a structural change to the hosting fabric itself: 196.251.107.104, a new node within AS214351 operated by Femo IT…
#AS214351#FemoITSolutions#Stealcv2#BazarLoader#Amadey#clipboardhijacker#bulletproofhosting#DGAdomainsIOCf20 · i3 · d2 · u5MITRE18RegionsAL · BO · CA · DE
C&CMembersMay 26, 2026, 21:02 (UTC+9)Dual-Cert Trojan VPN Pipeline Targets Food and Beverage Sector
Five Windows executables are circulating as components of a legitimate-looking VPN product — each carrying a valid-chain code-signing certificate issued to one of two shell entities, "INNOVATIVE CONNECTING PTE. LIMITED" and "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — while quietly establishing proxy-chain command-and-control infrastructure anchored in a Chengdu internet data centre.
#Barium#APT15#Cactus#ramnit#FoodBeveragesActorsBarium · Wicked SpiderIOCf10 · i18 · d23 · u3MITRE7IndustriesFood & Beverages
C&CMembersMay 26, 2026, 20:44 (UTC+9)Five Shell Companies, One Adware Campaign: DigiCert Cert Rotation Exposed
Thirty-one signed Windows binaries. Five distinct Chinese legal entities. One certificate authority. The Ludashi adware ecosystem — distributed under the guise of utility software products with names like LargeFileClean, WhaleMemory, Mem Optimization Pro, DupsClean, and CipherLock — has been running a sustained code-signing rotation strategy that goes well beyond what commodity adware operators typically invest in.
#FIN6#lockergoga#icedidActorsFIN6 · Skeleton SpiderIOCf31 · i4 · d12 · u8MITRE35
FILEMembersMay 26, 2026, 17:21 (UTC+9)APT27's KMS Activator Hides a Five-Year Evasion Framework
Six Windows executables. A self-extracting archive dressed as a software licence tool. A private certificate authority whose validity window stretches to 31 December 2039. Taken individually, each component of this toolset could be dismissed as a grey-market activation utility — the kind of software that circulates freely in environments where Windows licences are expensive and enforcement is lax.
#APT27#expiro#GovernmentActorsAPT27 · TEMP.HippoIOCf6 · i0 · d0 · u0MITRE23IndustriesGovernment
C&CMembersMay 26, 2026, 17:06 (UTC+9)Four Signed Certs, Ten IPs, One UnionPay Disguise: IcedID's Dual-Layer Evasion
Seventeen Windows executables and DLLs, all validly signed by DigiCert's Trusted G4 Code Signing chain, are circulating as system-cleaning and security utilities — and every one of them beacons to a C2 backend whose ten IP addresses present a wildcard TLS certificate issued to UnionPay International Co., Ltd. The combination is not accidental.
#icedidIOCf25 · i10 · d2 · u2MITRE46
C&CMembersMay 26, 2026, 16:51 (UTC+9)APT28 Burns Fake Cert, Hides Agent Behind Legit Vendor Signature
Two Windows executables, both signed with a freshly minted code-signing certificate issued to a shell identity called "Work Product Inc.," are circulating as a trojanized browser installer targeting the telecom sector — a signed-binary abuse chain [T1553.002] engineered to walk past execution controls before most endpoint tools have a chance to render a verdict.
#APT28#njrat#TelecommunicationsActorsAPT28 · StrontiumIOCf3 · i3 · d3 · u1MITRE6IndustriesTelecommunications
APTMembersMay 26, 2026, 16:35 (UTC+9)Two DigiCert Certs, 18 Signed Payloads, 14 Months Unrevoked
Eighteen Windows executables and DLLs have been circulating under the cover of two valid DigiCert Trusted G4 code-signing certificates, each issued to a distinct Chinese legal entity, across a campaign that CTX Team has tracked from November 2024 through at least January 2026. Both certificates remain unrevoked. Every file in the cohort passes Windows Authenticode validation without a SmartScreen warning.
#FIN6#SaltySpider#lockergoga#lummastealer#salityActorsFIN6 · Skeleton SpiderIOCf32 · i8 · d10 · u12MITRE19
FILEMembersMay 26, 2026, 11:35 (UTC+9)Expired UltraSurf Certificate Powers Stealthy C2 Campaign Against Finance
A UPX-packed Windows executable masquerading as the UltraSurf censorship-circumvention tool — signed with a GlobalSign-issued code-signing certificate that expired in June 2024 but still carries enough historical trust to fool the majority of the antivirus ecosystem — is being used to establish covert command-and-control tunnels toward freshly stood-up infrastructure on Hurricane Electric's network.
#MuddyWater#SilentChollima#Dalbit#hive#FinancialActorsMuddyWater · TEMP.ZagrosIOCf11 · i1 · d0 · u0IndustriesFinancial Services
FILEMembersMay 26, 2026, 11:05 (UTC+9)Vessel-Doc Phishing Campaign Adds Uncharacterised Hashes, Core Tradecraft Unchanged
A 901-kilobyte ZIP archive named MV_NATHAN_VSL_MAIN_PARTICULARS+Q88_DETAILS.zip is doing quiet work across at least thirteen countries. The file — first seen on VirusTotal on 2026-05-13 and submitted from two independent sources on the same day — carries a single embedded PE32 .NET assembly whose .text section registers entropy of 7.88, near the theoretical maximum, and declares zero imports.
#AgentTesla#APT29#MSILstealer#maritimesector#spearphishing#geolocationevasion#packed.NET#credentialtheftActorsAPT29 · MinidionisIOCf4 · i0 · d0 · u0MITRE47RegionsAU · CZ · DE · EGIndustriesEngineering · Financial Services · Manufacturing
C&CMembersMay 26, 2026, 10:47 (UTC+9)Spring Dragon Hides SQL Implant in Signed Netease Emulator, Fools All 76 AV Engines
A 24-megabyte Windows executable presenting as the legitimate Netease MuMuPlayer Android emulator has cleared every antivirus engine that examined it — all 76 of them — while simultaneously triggering a YARA rule identifying byte patterns consistent with the SKIP-2.0 SQL Server authentication-bypass implant. The binary carries a valid, unrevoked DigiCert-rooted code-signing certificate issued to Netease Interactive Entertainment Pte.
#SpringDragon#wmi_ghost#EducationResearch#TechnologyActorsSpring Dragon · Lotus BlossomIOCf2 · i0 · d4 · u1MITRE4IndustriesEducation & Research · Technology
C&CMembersMay 26, 2026, 10:27 (UTC+9)Two DigiCert Certificates, 16 Malicious Binaries, Nine Months Unrevoked
Sixteen Windows executables bearing currently-valid DigiCert G4 code-signing certificates have been circulating across Chinese-language software distribution channels since at least August 2025, impersonating disk-cleaners, QQ-cleanup utilities, zip tools, and browser-guard products — a signed-binary abuse chain [T1553.002] that walks past Windows SmartScreen and suppresses the heuristic engines that most enterprise endpoints rely on.
#TA511ActorsTA511 · MAN1IOCf26 · i8 · d3 · u3MITRE4
APTMembersMay 26, 2026, 10:12 (UTC+9)Trojanized Adware Chain Hides Behind Bank's TLS Identity for 12 Months
Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 have been circulating as trojanized PC-utility components since at least May 2025 — all signed under a single certificate serial (0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0) that remains unrevoked and valid through May 2027.
#FIN6#lockergoga#lummastealer#expiro#TelecommunicationsActorsFIN6 · Skeleton SpiderIOCf20 · i18 · d0 · u1MITRE8IndustriesTelecommunications
APTMembersMay 26, 2026, 09:59 (UTC+9)Single EV Certificate Signed Trojan.Jumper Trio Across Nine Sectors
A trojanised VPN installer toolchain — three PE32 binaries all bearing a single GlobalSign Extended Validation certificate issued to "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — has been circulating across nine industry verticals since at least September 2025, using a curated software-recommendation channel as its entry point and a three-tier command-and-control architecture to evade both sandbox analysis and network-level detection.
#TA551#EducationResearch#Engineering#Financial#FoodBeverages#GovernmentActorsTA551 · ShathakIOCf3 · i4 · d2 · u1MITRE29IndustriesEducation & Research · Engineering · Financial Services
APTMembersMay 26, 2026, 09:41 (UTC+9)APT23 Runs 18-Month Signed-Binary Campaign Behind Chinese Corporate Certs
Eight Windows executables have been circulating across Chinese-language computing environments since at least November 2024, each carrying a valid, unexpired DigiCert G4 code-signing certificate issued to one of three distinct Chinese corporate entities — and each producing uniformly clean verdicts in automated sandbox environments despite antivirus detection ratios that range as high as 34 out of 76 engines.
#APT23#lummastealer#icedid#neshtaActorsAPT23 · KeyBoyIOCf12 · i2 · d9 · u11MITRE13