CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • APTMembersMay 24, 2026, 17:57 (UTC+9)

    One Unrevoked Certificate, 17 Payloads, Eleven Months of Signed Adware

    Seventeen distinct Windows executables. Six product identities. Eleven months of continuous distribution. All of it bound together by a single DigiCert G4 code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co., Ltd.) — a certificate that, as of this writing, remains valid, unrevoked, and good until May 2027.

    #FIN6#Group123#SaltySpider#lockergoga#lummastealer#sality
    ActorsFIN6 · Skeleton SpiderIOCf34 · i3 · d6 · u6MITRE11
  • C&CMembersMay 24, 2026, 17:57 (UTC+9)

    Six Shell Companies, One Builder: DigiCert Certs Fuelled 14-Month Signed-Malware Run

    Thirty-four Windows executables carrying valid DigiCert Trusted G4 Code Signing certificates — each issued to a distinct Chinese company identity — have been circulating since October 2024, disguised as consumer PC-utility software: file cleaners, memory optimisers, browser protectors, and QQ-related tray applications. The signing identities rotate. The build toolchain does not.

    #FIN6#TA428#lockergoga#ncctrojan#icedid
    ActorsFIN6 · Skeleton SpiderIOCf34 · i13 · d11 · u10MITRE23
  • FILEMembersMay 24, 2026, 17:57 (UTC+9)

    Snowglobe Backdoor Hides in GTA V Launcher to Hit Thai Telecoms

    A 32-bit Windows executable named "Grand Theft Auto V Enhanced.exe" — one of four GTA V-branded filename variants circulating in this campaign — is not what it claims to be. Behind the high-recognition game title sits a Babar-family backdoor attributed to the Snowglobe actor cluster (also tracked as Animal Farm and Sig20), directed at telecommunications operators in Thailand under an espionage mandate.

    #Snowglobe#babar#Telecommunications
    ActorsSnowglobe · Animal FarmIOCf4 · i0 · d1 · u0MITRE21RegionsTHIndustriesTelecommunications
  • FILEMembersMay 24, 2026, 15:23 (UTC+9)

    Revoked EV Cert and CloudFront CDN Power 32-Country Installer Campaign

    Two Windows PE32 installers, both bearing a Sectigo Extended Validation code-signing certificate issued to an entity called "Plooto Star Inc," were signed within sixty seconds of each other on the afternoon of September 21, 2025 — and by the time either file appeared on VirusTotal five days later, that certificate had already been revoked by its issuer.

    #DustSquad#lummastealer#Consulting#EducationResearch#Financial#Government
    ActorsDustSquad · APTC34IOCf2 · i0 · d1 · u0MITRE18RegionsBJ · BR · CI · ECIndustriesConsulting · Education & Research · Financial Services
  • C&CMembersMay 24, 2026, 14:51 (UTC+9)

    APT28 Deploys Validly Signed Chrome Fake, Gets Zero Detections

    A 4-megabyte Windows executable masquerading as Google Chrome is circulating with a valid, unexpired Google LLC code-signing certificate — and every one of the 76 antivirus engines that examined it returned a clean verdict. That single data point, drawn from CTX Team's analysis of a cluster attributed to APT28 (also tracked as Fancy Bear, Forest Blizzard, and approximately 17 other aliases), captures the operational logic of the entire campaign: when a binary carries a legitimate certificate…

    #APT28#Government
    ActorsAPT28 · StrontiumIOCf2 · i1 · d3 · u6MITRE4IndustriesGovernment
  • C&CMembersMay 24, 2026, 14:38 (UTC+9)

    WHQL-Signed Driver Blinds EDR a Year Before Crypto Theft Wave

    A 34-kilobyte Windows kernel driver — signed with a legitimate Microsoft Hardware Compatibility Publisher certificate, bearing Safetica copyright strings, and detected by exactly two of 76 antivirus engines — was quietly staged on victim systems as early as May 2025. Nearly a year later, a coordinated wave of credential stealers, clipboard hijackers, and browser wallet harvesters began appearing in the wild, all beaconing to a two-IP cluster in a small, recently allocated autonomous system.

    #TA428#WizardSpider#pythonstealer#vulcan
    ActorsTA428 · ThunderCatsIOCf25 · i3 · d1 · u9
  • APTMembersMay 24, 2026, 14:01 (UTC+9)

    Salty Spider Hides RAT in Signed Bundles via Two DigiCert Certs

    Twenty malicious Windows executables and DLLs have been circulating under valid DigiCert G4 code-signing certificates issued to two Chinese-registered front entities — a dual-certificate architecture that has remained unrotated across a fifteen-month active build window while the operator quietly embedded a PubNubRAT remote-access capability inside what presents to users as a routine system-utility bundle.

    #SaltySpider#sality
    ActorsSalty Spider · KuKuIOCf33 · i7 · d6 · u5MITRE14
  • APTMembersMay 24, 2026, 13:30 (UTC+9)

    Cactus Group Abuses Three Signing Identities to Hide PBot Stealer in VPN Lures

    Nine Windows executables circulating across software-distribution channels share a single operational logic: every one of them carries a legitimate code-signing certificate — or a certificate that was legitimate until recently — and every one of them is doing something the signer never intended. Six files exploit expired-but-chain-valid EV and OV certificates from two distinct corporate identities to suppress antivirus detection on trojanized VPN installers.

    #Cactus#ramnit
    ActorsCactus · Cactus Ransomware GroupIOCf16 · i46 · d118 · u16MITRE16
1Of
13
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.