CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • C&CMembersAug 9, 2026, 10:54 (UTC+9)

    Chinese Adware Ring Reuses Certs to Spoof UnionPay and Huawei

    Every piece of command infrastructure in this record — all seven IP addresses tied to the cluster — sits on a single Chinese carrier backbone, AS4837, CHINA UNICOM China169 Backbone. That alone would be a footnote for China-facing infrastructure. What makes it a story is what those IPs present to anyone who connects to them: two separate, duplicated TLS certificates, each spoofing a different trusted brand.

    #code-signingabuse#TLScertificatespoofing#UnionPayimpersonation#HuaweiAppGalleryspoofing#ChinaUnicomAS4837#ludashiadware#anti-analysistechniques#PUAdistribution
    IOCf28 · i7 · d0 · u0MITRE14
  • APTMembersAug 9, 2026, 10:45 (UTC+9)

    Old RemCom Hacktool Masks a Clean-Scoring WinSW Impostor

    A remote-command-execution hacktool compiled on 2012-08-09 is still being resubmitted under randomized filenames as recently as July 2026, flagged by 46 of 75 engines and matched by three named YARA rules — and sitting in the same indicator set is a 16.8-megabyte binary posing as the open-source WinSW Windows Service Wrapper that clears every one of 77 antivirus engines outright.

    #RemCom#WinSWimpersonation#lateralmovement#bulletproofhosting#Proton66#Flyservers#njRAT#Cactusransomwaregroup
    ActorsCactus · Cactus Ransomware GroupIOCf2 · i13 · d0 · u0MITRE20
  • FILEMembersAug 9, 2026, 01:56 (UTC+9)

    Fake Root CA Signs Pirated KMS Activation Tools

    Four Windows activation cracks distributed under the KMSpico and AutoKMS names carry an identical code-signing chain — but the authority that issued it isn't Sectigo, DigiCert, or any of the trust roots Windows ships with. It's "@ByELDI Certificate Authority," a self-manufactured root the operators built themselves, and every certificate under it fails Windows' own validation check.

    #KMSpico#AutoKMS#codesigningabuse#self-signedcertificate#piratedsoftware#dynamicDNS#anti-analysistechniques#Patchwork
    ActorsPatchwork · ChinastratsIOCf14 · i1 · d1 · u1MITRE51
  • APTMembersAug 9, 2026, 01:46 (UTC+9)

    A Disposable AWS Front and a CDN Wildcard Are the Real Story, Not the File

    Two pieces of infrastructure — a beacon domain delegated through Amazon's own nameservers and a CDN-fronted IP wearing someone else's wildcard certificate — carry far more evidential weight in this record than the single file attached to it. The domain, wb.sleevesbarbing.com, resolves through eight rotating A-records behind AWS Route53 delegation and serves six URLs that all follow the identical templated path /mtn/130079/<32-character-hash>.<epoch-timestamp>.000.

    #AWSRoute53delegation#CDNwildcardcertificate#AdvancedIPScanner#Famatechcodesigning#Edgenextinfrastructure#telecomsectortargeting#disposableC2domain#expiredcertificatechain
    ActorsLockbit GangIOCf1 · i1 · d1 · u6MITRE4IndustriesTelecommunications
  • FILEMembersAug 9, 2026, 00:27 (UTC+9)

    One Code-Signing Certificate Covers 14 WaveBrowser Bundleware Files

    A single leaf certificate — serial 09 D7 7A 45 C1 C0 97 55 AE 3E 7A 51 53 98 3C 03, issued to "Wavesor Software (Eightpoint Technologies Ltd. SEZC)" under the DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 chain — signs all fourteen core binaries CTX Team has catalogued for a browser-and-updater bundle marketed as WaveBrowser and its companion SWUpdater service.

    #codesigningcertificateabuse#bundleware#WaveBrowser#SWUpdater#PUA/adware#sandboxevasion#Authenticodetrust#misattribution
    ActorsAPT28 · StrontiumIOCf16 · i1 · d0 · u0MITRE9IndustriesEducation & Research
  • FILEPublicAug 8, 2026, 23:59 (UTC+9)

    Signed Process Hacker Driver Now Anchors a Four-Stage Attack Chain

    A signed kernel driver that Microsoft's own trust chain still vouches for is quietly doing double duty as a privilege-escalation primitive, and it is not travelling alone. The newest indicators added to a long-tracked Process Hacker 2 file set — both the x86 and x64 builds of kprocesshacker.sys (0f97f6d53fff…, 70211a3f9037…) — fire the LOLDrivers-catalogued rule PUA_VULN_Driver_Wj_Kprocesshacker_7021 despite carrying a fully valid DigiCert code-signing chain.

    #ProcessHacker#BYOVD#kprocesshacker.sys#LOLDrivers#NirSoft#credentialtheft#signedmalware#kernelprivilegeescalation
    ActorsRoyal Ransomware · Team OneIOCf35 · i0 · d0 · u0IndustriesGovernment
  • APTMembersAug 8, 2026, 23:04 (UTC+9)

    Windows Defender-Killer Tool Folded Into XRed RAT Dropper

    A commodity tool built to switch off Windows Defender with one click has turned up inside the build of a remote-access-trojan dropper — not dropped alongside it, but sharing the same crowdsourced YARA signature. The standalone hacktool, tracked publicly as DefenderControl and carried in this set as 1ef6c1a4dfdc39b63bfe650ca81ab89510de6c0d3d7c608ac5be80033e559326, and a Synaptics-driver-themed dropper that sandboxing names as the XRed RAT,…

    #GorgonGroup#Subaat#XRedRAT#DefenderControl#HongKongtechnologysector#dynamicDNSabuse#masqueradetechnique#espionage
    ActorsGorgon Group · SubaatIOCf15 · i1 · d0 · u0MITRE29RegionsHKIndustriesTechnology
  • C&CMembersAug 8, 2026, 20:44 (UTC+9)

    Valid Bright Data Signature Found on EarnApp Installers Flagged as PBot Stealer

    Four Windows installers branded as EarnApp — the passive-income tool that pays users to resell idle bandwidth through Bright Data's proxy network — carry a fully valid Bright Data Ltd code-signing chain from DigiCert, and two of them are independently flagged by a sandbox as the "PBot" stealer family. That combination is the story here, not because a certificate was forged or revoked, but because it wasn't.

    #EarnApp#BrightData#PBotstealer#code-signingabuse#DigiCert#supply-chaintrustabuse#proxyware#bandwidth-sharingmalware
    IOCf69 · i22 · d98 · u9MITRE4IndustriesCommercial Services
  • FILEPublicAug 8, 2026, 19:48 (UTC+9)

    One Trojan Sample Shows Full Evasion Playbook, No Campaign in Sight

    A Win32 executable currently flagged by 61 of 76 antivirus engines packs a textbook sandbox-evasion triad — checking for an attached debugger, reading the CPU clock directly, and inspecting the CPU model string — into a single unsigned dropper that has circulated under at least four unrelated decoy filenames since 2016. What makes the sample newsworthy is not a hosting cluster or a signing certificate; there is neither.

    #trojan.python/fkuk#stitchmalwarefamily#sandboxevasion#WMIdiscovery#HolyWater#StormCloud#persistencetechniques#lurefilenames
    ActorsHolyWater · Storm CloudIOCf1 · i0 · d0 · u0IndustriesEducation & Research
  • C&CMembersAug 8, 2026, 19:39 (UTC+9)

    Fake UnionPay TLS Certificate Ties Together 19 Chinese Adware Hosts

    Nineteen IP addresses scattered across five or more distinct Chinese ISPs — China Unicom's China169 backbone, three separate China Mobile autonomous systems, and a scatter of regional China Telecom blocks — all present the identical TLS certificate when a browser connects to them. The subject line reads *.unionpayintl.com, organisation "UnionPay International Co., Ltd.," issued by DigiCert's Basic OV G2 TLS CA.

    #UnionPayimpersonation#wildcardTLScertificate#Ludashi#Chinad#PolarWind#codesigningabuse#APT23#adwaredistributioninfrastructure
    ActorsAPT23 · KeyBoyIOCf17 · i23 · d2 · u0MITRE7
  • APTMembersAug 8, 2026, 19:30 (UTC+9)

    Valid Code Signatures Mask PBot Stealer in VPN/Proxy Installers

    A Windows installer branded as Bright Data's residential-proxy SDK carries a complete, unbroken DigiCert code-signing chain — and still returns a sandbox verdict naming the PBot stealer classification. Across ten files reviewed by CTX Team, three separate code-signing identities — Bright Data Ltd, WEILAI NETWORK TECHNOLOGY CO., LIMITED, and INNOVATIVE CONNECTING PTE.

    #PBotstealer#code-signingabuse#proxyware#BrightData/Luminati#WireVPN#VPNMaster#DigiCert#PUA
    ActorsEmotet Group · TA542IOCf15 · i36 · d51 · u10MITRE22
  • C&CMembersAug 8, 2026, 14:23 (UTC+9)

    One Chinese Certificate Signed Nine Months of Ludashi Adware Builds

    The most durable piece of infrastructure behind a sprawling family of Chinese system-utility adware is not a server or a domain — it is a single code-signing certificate. Eight of nine binaries examined in this cluster carry an identical signer chain: 成都奇鲁科技有限公司, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert's root, with certificate serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98.

    #Ludashiadware#code-signingcertificateabuse#ChinaD#UnwantedX#wildcardTLScertificate#China-basedinfrastructure#adwareC2#PUAdistribution
    ActorsFIN6 · Skeleton SpiderIOCf9 · i2 · d4 · u3MITRE11
  • APTMembersAug 7, 2026, 06:05 (UTC+9)

    Old Macro-to-PowerShell Emotet Chain Still Fools Every Sandbox

    A macro-laced Word document circulating against United States education and research targets is producing a rare thing in modern detection telemetry: unanimous agreement. All three sandboxes that processed the sample — C2AE, ReaQta-Hive, and BitDam ATP — return a "malicious" verdict, and 43 of 75 antivirus engines flag the file outright.

    #Emotet#TA542#macromalware#PowerShelldownloader#educationsector#masquerading#Let'sEncryptcertificates#loader-for-hire
    ActorsEmotet Group · TA542IOCf3 · i1 · d2 · u5RegionsUSIndustriesEducation & Research
  • C&CMembersAug 6, 2026, 22:12 (UTC+9)

    C2 Cluster Adds 9 IPs, 20 Domains — Just 5 New Files

    Nine new IP addresses and twenty new domains have surfaced around a C2-server cluster CTX Team has been tracking since earlier coverage of a campaign built on trojanized VPN and proxy installers ("Two Vendor Signatures, One Stealer"). Only five new files joined the set in the same window. That lopsided ratio is itself the story: the operators are not retooling their malware, they are aggressively provisioning and rotating the network fabric that fronts it.

    #C2infrastructure#trojanizedinstallers#WireVPN#BrightDataimpersonation#certificatereuse#SpacePirates#Cactus#disposableinfrastructure
    ActorsSpace Pirates · WebwormIOCf14 · i21 · d47 · u6MITRE16
  • C&CMembersAug 5, 2026, 22:13 (UTC+9)

    Batch-Signed Adware Beats AV Detection, Fools Every Sandbox

    A code-signing certificate issued to a company called Shenzhen Kaixin Kangaroo Technology Co., Ltd. was used to sign eight different executables and DLLs — all in the same eight-minute window on March 20, 2024. A separate certificate, issued this time to Shanghai Oriental Webcasting Co. Ltd., produced the same pattern two months later: seven of eight files signed within a single minute on May 29, 2024.

    #code-signingcertificateabuse#adware#PUA#GoodZip#WanNengWBInput#APT27#SaltySpider#ChinaCDNinfrastructure
    ActorsAPT27 · TEMP.HippoIOCf30 · i14 · d1 · u1MITRE24
  • APTMembersAug 5, 2026, 22:04 (UTC+9)

    Wizard Spider Kit Adds Stealer-to-Downloader Handoff, C2 Unchanged

    The kit CTX Team has tracked under this cluster just picked up a matched pair of new files, and they slot together like a delivery chain missing its middle link. A stealc-tagged dropper — carried under the path %APPDATA%\crkhost.exe and flagged malicious by 55 of 76 engines — and a downloader dressed as a Windows service process, taskhostw.exe (also seen as WinUpdateHelper.exe, 46/76 detections), both first appeared within a 24-hour window in early May and both share a single YARA signature:…

    #WizardSpider#Stealc#credentialtheft#vulnerabledriverabuse#hostsfiletampering#certificateimpersonation#AS214351#commandandcontrolinfrastructure
    ActorsWizard Spider · Grim SpiderIOCf5 · i3 · d0 · u6MITRE25RegionsJOIndustriesFood & Beverages
  • FILEMembersAug 5, 2026, 11:49 (UTC+9)

    Pirated Windows Activator Bundle Hides Shared Base64 Execution Trick

    A "Microsoft Activation Scripts" archive built to bypass Windows and Office licensing is now doubling as a delivery mechanism for base64-encoded PowerShell payloads — and the same authoring fingerprint shows up in two structurally different file types inside the same drop. Eight of nine files tied to this indicator set carry file paths referencing "MAS/Separate-Files-Version" or "MAS/All-In-One-Version-KL," all first appearing within a 48-hour window between July 4 and July 6, 2026.

    #TA505#rockloader#hacktool.autokms#hacktool.kmsauto#base64PowerShellexecution#KMSactivationpiracy#WindowsOfficelicensing#.winTLDDNScallback
    ActorsTA505 · Hive0065IOCf10 · i1 · d0 · u0MITRE13
  • C&CMembersAug 5, 2026, 11:41 (UTC+9)

    Two Vendor Signatures, One Stealer: VPN Installers Abuse Trust Chains

    Three files circulating under VPN branding this year carry a code-signing chain that VirusTotal's own signer inspection flags as broken. The signer field reads "WEILAI NETWORK TECHNOLOGY CO., LIMITED," countersigned through GlobalSign GCC R45 EV CodeSigning CA 2020, and every one of the three samples' signer-details blocks returns the same line: "This certificate or one of the certificates in the certificate chain is not time valid." That should be a hard stop for any endpoint relying on…

    #code-signingabuse#PBotstealer#BrightData#WEILAINETWORKTECHNOLOGY#VPNinstallertrojan#fast-fluxhosting#Let'sEncryptabuse#SpacePirates
    ActorsSpace Pirates · WebwormIOCf9 · i15 · d27 · u3MITRE17
  • APTMembersAug 5, 2026, 05:34 (UTC+9)

    Fake YCleaner Hides PowerShell Fetch Loop Behind Spoofed AV Certificate

    A "system cleaner" branded YCleaner wraps a multi-stage dropper chain that leans on a spoofed antivirus-vendor certificate and a single PowerShell-invoked downloader signature reused across three separate binaries — and stages its final payload inside a ZIP archive that, as of this writing, zero of 77 scanning engines flag as malicious. The domain feeding the chain, adobehelp.net, carries a nameserver record that contradicts its own WHOIS listing.

    #YCleaner#PowerShelldownloader#fakesystemcleaner#BlueBottle#adobehelp.net#code-signingspoofing#encryptedarchiveevasion#Malaysia
    ActorsBlueBottle · Opera1erIOCf16 · i0 · d1 · u2MITRE29RegionsMY
  • FILEMembersAug 4, 2026, 13:47 (UTC+9)

    Validly Signed uTorrent Installer Hides Trojan.Offercore

    An executable calling itself utorrent_installer.exe carries a fully valid four-tier code-signing chain — BitTorrent Inc, chained up through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 to DigiCert Trusted Root G4 — and yet 18 of 76 engines still flag it as trojan.offercore/r783575. That combination is the story here: not a forged certificate, but a genuine one riding on top of a payload the security industry has learned to distrust.

    #trojan.offercore#code-signingabuse#uTorrent#anti-sandboxevasion#CloudFrontinfrastructure#P2Ptrafficmimicry#adware/PUP#TLScertificatespoofing
    IOCf28 · i4 · d2 · u0MITRE48RegionsAD · AE · AL · AMIndustriesChemicals · Commercial Services · Construction
  • APTMembersAug 4, 2026, 05:33 (UTC+9)

    Donot Team Ties Three Domain Clusters via 89-Day Cert Cadence

    Five domains, three registrars, three continents' worth of WHOIS geography, and not a single shared owner on paper — yet every one of them carries an identical 89-day Let's Encrypt certificate validity window. That convergence, surfaced across a Thai medical-software vendor's subdomain fleet, an AWS Route53-fronted delivery node registered through a Panama privacy proxy, and a decade-old Japanese domain flagged for compromise, is the strongest signal in this indicator set — stronger, in fact,…

    #DonotTeam#APTC35#SectorE02#certificateprovisioning#spearphishing#healthcaretargeting#AWSRoute53abuse#domainhijacking
    ActorsAPTC35 · Donot TeamIOCf7 · i0 · d5 · u15MITRE18IndustriesGovernment · Healthcare · Telecommunications
  • FILEMembersAug 3, 2026, 21:49 (UTC+9)

    Old Allaple Worm Label Reused on Adobe-Masquerading HTML Droppers

    Three HTML files carrying VirusTotal's family label "trojan.allaple" — 1102b8a9933b2191f1b80bd9bc478f301536216332ddf2986d3ffc792474be3d, 7768dae586920feac88943b260caa4f9a26bd357603d81517431d38f5e026594, and eb333a956be00c99c0d2523fabbea40f08ce65f5120e2744a24a5fb3abbfa3b7 — were submitted between April and August 2024, and two of them stage themselves under file paths built to look like legitimate Adobe software.

    #Allaple#HTMLdropper#masquerading#embeddedJavaScript#sandboxevasion#AT&Tinfrastructure#Germanresearchnetwork#malwarefamilyreuse
    IOCf33 · i34 · d0 · u0MITRE24RegionsUSIndustriesRetail
  • APTMembersAug 3, 2026, 21:35 (UTC+9)

    A Builder Stub That Outlived Four Different Malware Labels

    Cybercrime taxonomies love clean boundaries — XWorm here, Amadey there, a "msilheracles" trojan somewhere else. But a set of Windows binaries CTX Team has been tracking, tagged in upstream telemetry to APT28-associated activity, shows how thin those labels can be. Four samples that public detection engines classify as four unrelated families — a 2024 XWorm loader, a 2023 Amadey downloader, and two "QCoin"-branded .NET binaries dating back to December 2017 — all carry the exact same import-table…

    #APT28#XWorm#Amadey#DarkKomet#XRed#imphashreuse#timestomping#masquerading
    ActorsAPT28 · StrontiumIOCf35 · i7 · d2 · u6MITRE100
  • APTMembersAug 3, 2026, 13:34 (UTC+9)

    Fake reCAPTCHA Lure Tied to Dedicated Host via Certificate Match

    A domain calling itself verifyrecapcha.info is not, in fact, a CAPTCHA. It is a phishing front end that mimics the verification interstitial Google uses to separate humans from bots, and it has been flagged by 19 of 91 security engines — a detection band that puts it firmly in known-bad territory even before the infrastructure underneath it is examined.

    #Tortilla#phishinginfrastructure#fakereCAPTCHA#TLScertificatepivot#Cloudflarefronting#resellerhosting#espionage#PDR/DirectiASN
    ActorsTortillaIOCf0 · i4 · d2 · u1MITRE10IndustriesArts & Entertainment
  • C&CMembersAug 3, 2026, 05:32 (UTC+9)

    APT28-Tagged Cluster Shows 89-Day Cert Pattern, No Malware

    Three domains with nothing else in common — different registrars, different creation dates, different Let's Encrypt intermediates — share one oddly precise trait: certificates valid for exactly 89 days. ccu.to, swisscutterastronaut.com, and each-task.com were issued certificates by three separate Let's Encrypt intermediates (R13, YR2, and YE1, respectively), yet all three validity windows run to the same 89-day span.

    #APT28#FancyBear#Let'sEncryptcertificates#certificatecloning#C2infrastructure#domainregistrationfraud#espionage#TencentCDN
    ActorsAPT28 · StrontiumIOCf0 · i5 · d7 · u0MITRE4IndustriesContainers & Packaging
  • APTMembersAug 2, 2026, 21:35 (UTC+9)

    VPN Trojan Cluster Adds 10 IPs, 6 Domains, No New Malware

    The latest pass through this VPN-and-proxy-trojan operation surfaces ten additional IP addresses and six additional domains — and not a single new malicious binary. That lopsided delta is itself the story. While the signed installers that anchor this campaign have sat unchanged for months, the network layer underneath them keeps expanding, and the clearest evidence of that expansion is a single TLS certificate serial, 363a6b88ee219be351b40934, now confirmed live on four separate hosts spread…

    #VPNtrojan#proxymalware#certificateabuse#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTING#BrightData#China#Philippines
    ActorsUAC-0063 · TAG-110IOCf35 · i21 · d15 · u4MITRE21IndustriesTechnology
  • FILEMembersAug 2, 2026, 05:49 (UTC+9)

    Fake Shipping Documents Deliver AgentTesla Stealer Under Five Packers

    The payload doesn't look like malware when it lands in an inbox. It looks like a vessel particulars sheet — "MV TBN SHIP PARTICULARS.docx.exe," "SHIP PARTICULARS - MV OSTC01.xlsx.exe," "MV PACIFIC ENDEAVOR V2202 PARTICULARS I.docx.exe." Each of those alternate filenames belongs to the same 490KB Windows executable, a double-extension trick that hides an EXE behind a familiar Word or Excel icon — a lure built for whoever in a shipping or freight-forwarding chain is used to receiving cargo…

    #AgentTesla#spear-phishing#maritimeshippinglure#double-extensionmalware#.NETobfuscation#SMTPexfiltration#APT29misattribution#commodityinfostealer
    ActorsAPT29 · MinidionisIOCf9 · i0 · d2 · u0MITRE38
  • C&CMembersAug 2, 2026, 05:41 (UTC+9)

    Fake Baidu, Alibaba TLS Certs Mask Five-Year RAT Campaign

    Ten IP addresses tied to a single threat-intelligence record show almost no malicious signal on their own — nine come back 0/91 on antivirus scanning, one scrapes a single flag at 1/91. Yet three of those IPs pair up with a twin elsewhere on the internet through an identical TLS certificate, and each pairing wildcards a domain the certificate's real owner has nothing to do with. Two Alibaba Cloud-registered addresses share one GlobalSign-issued certificate for .certfallback.com.

    #XRedRAT#certificatereuse#TLSimpersonation#Baiduspoofing#AlibabaCloud#ChinaUnicom#APT28attribution#dynamicDNSC2
    ActorsAPT28 · StrontiumIOCf13 · i10 · d0 · u0MITRE40RegionsTW
  • APTMembersAug 2, 2026, 05:31 (UTC+9)

    Expired Certificates Keep Signing Trojanized VPN Installers

    The most durable piece of tradecraft in this campaign isn't a novel loader or a clever injection technique — it's a pair of Authenticode certificates that have been technically invalid for months and are still being used to sign new builds. Two code-signing identities, WEILAI NETWORK TECHNOLOGY CO., LIMITED (chained through GlobalSign GCC R45 EV CodeSigning CA 2020) and INNOVATIVE CONNECTING PTE.

    #code-signingabuse#certificatechainmanipulation#VPNtrojan#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTING#Philippinetelecominfrastructure#TLScertificatereuse#supply-chaincompromise
    ActorsUAC-0063 · TAG-110IOCf74 · i13 · d13 · u3MITRE22IndustriesTechnology
  • APTMembersAug 1, 2026, 21:36 (UTC+9)

    Adware Operator Re-Signs Same Stale Build Across Two CAs

    A twelve-file Authenticode cohort tied to a Windows browser product called "OneBrowser" shows something unusual for a piece of adware: the operator kept re-signing the same eight-month-old executable under a fresh certificate every time the previous one lapsed. The pattern surfaces in a batch of files carrying the identical certificate serial 0E F9 0B 20 6A 1B 07 82 E0 D0 FD 33 88 24 EC 42, issued under a GoGetSSL G4 CS RSA4096 chain rooted in DigiCert, with Authenticode signing dates falling…

    #OneBrowseradware#codesigningabuse#Authenticodecertificatechurn#PUAdistribution#APT28misattribution#WorkProductInc#browserhijacking#threatinteltagging
    ActorsAPT28 · StrontiumIOCf18 · i0 · d2 · u44MITRE8IndustriesTelecommunications
  • C&CMembersAug 1, 2026, 05:38 (UTC+9)

    EV Certificate Lets ORYON Adware Suite Slip Past Sandbox Scans

    Four differently named Windows installers — AdvancedWindowsManager.exe, Windows Updater.exe, Installer_1.0.0.exe and an MSI package called e78a2.msi — carry the exact same code-signing chain: ORYON TECH LIMITED, chaining through Sectigo Public Code Signing CA EV R36 and Sectigo Public Code Signing Root R46, all signed at the identical timestamp of 08:36 AM on 04/23/2026. That precision is the story.

    #ORYONTECHLIMITED#EVcodesigningabuse#microleavesadware#sandboxevasion#pay-per-install#Cloudflareredirectordomains#QuickFetchloader#PUPdistribution
    IOCf20 · i1 · d5 · u15MITRE22RegionsBE · CA · DZ · GBIndustriesRetail · Technology
  • FILEMembersJul 31, 2026, 21:52 (UTC+9)

    Revoked Certs and a 1992 Timestamp: A Hacktool Kit That Won't Die

    The most striking fact in this 46-file batch isn't a new malware family — it's that the tools are old, freely available, and still working. Four driver and library builds of the open-source credential-dumping tool mimikatz, including the file hashed bd177792a573f81a96c7ca9833ab7090eb8a5ea0491d1b1381efc2a5ac3f54b0, continue to carry Benjamin Delpy's original code-signing chain years after the underlying certificates were explicitly revoked by their issuers.

    #mimikatz#Neshta#NirSoft#revokedcode-signingcertificates#credentialdumping#dual-usetools#LSASS#imphash
    ActorsRoyal Ransomware · Team OneIOCf46 · i0 · d0 · u0MITRE19
  • APTMembersJul 31, 2026, 21:36 (UTC+9)

    Signed Chinese Input-Method Suite Hides IcedID-Flagged Loader

    Four Windows binaries branded as 万能五笔输入法 — a legitimate Chinese Wubi input-method suite — carry an identical Extended Validation code-signing certificate, the same build timestamp, and, in two cases, a payload signature tied to the IcedID malware family, even though the sandboxes that examined them returned a clean verdict. The pairing of trusted EV signing with a static loader-kit fingerprint that slips past dynamic analysis is the sharpest signal in a nine-file, nine-IP cluster CTX Team has…

    #APT27#IcedID#code-signingabuse#BYOVD#kerneldriver#CDNimpersonation#China#supplychaintrojan
    ActorsAPT27 · TEMP.HippoIOCf9 · i9 · d0 · u0MITRE11
  • C&CMembersJul 31, 2026, 13:43 (UTC+9)

    Two 'Rival' Chinese Software Brands Share One Signing Chain

    Fourteen signed Win32 binaries surfaced carrying the trusted names of two separate Chinese software vendors — a "万能五笔输入法" input-method utility from Shanghai Oriental Webcasting Co. Ltd. and a "2345看图王" photo-viewer suite from Shanghai 2345 Mobile Technology Co., Ltd. — yet both cohorts chain to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root, and a single YARA rule fires across samples signed by each.

    #adware#codesigningabuse#DigiCert#China#CDNinfrastructure#YARAfingerprint#Group123/APT37misattribution#Salitymisattribution
    ActorsGroup123 · Venus 121IOCf14 · i6 · d0 · u0MITRE28
  • APTMembersJul 31, 2026, 13:33 (UTC+9)

    Decade-Spanning Cert Cohort Exposes Cactus's Standing Provisioning Pipeline

    Four domains that share nothing else — not a registrar, not a top-level domain, not even a decade of age — converge on the same certificate authority, the same 89-day validity window, and an issuance timeline packed into roughly two months. 5.tipsy.co.za has been registered since 2013; presidencycollege.in surfaced in 2024 and sat dormant until this year.

    #Cactus#YR1certificatecohort#Gname.com#DigiCertG4signingchain#PBotstealer#domaingenerationalgorithm#phishingdomainreactivation#telecommunicationssector
    ActorsCactus · Cactus Ransomware GroupIOCf23 · i3 · d9 · u0IndustriesTelecommunications
  • C&CMembersJul 31, 2026, 05:44 (UTC+9)

    Shared Certificates, Not Payloads, Tie Five Emotet-Linked Domains

    Five domains and a single Hostinger-hosted IP address form a hosting cluster that looks less like purpose-built command infrastructure and more like a disposable inventory kept in circulation for years. Across the set, two distinct certificate-issuer cohorts and a shared nameserver pairing tie the nodes together with far more precision than anything the lone piece of file telemetry in this record can offer. The strongest signal here isn't a payload — it's the paperwork.

    #Emotet#TA542#C2infrastructure#Let'sEncryptcertificates#domainreuse#Hostinger#educationsector#macrodownloader
    ActorsEmotet Group · TA542IOCf3 · i1 · d5 · u2RegionsUSIndustriesEducation & Research
  • APTMembersJul 31, 2026, 05:34 (UTC+9)

    A Revoked 2014 Certificate Still Signs the Same Adware Family

    Four binaries tied to a Windows "PC optimization" installer chain — an EXE, its setup-extraction temp copy, and two helper DLLs — all carry the identical code-signing leaf certificate issued to "PC Utilities Software Limited," serial 00 CF 20 ED FB 9E 9D 56 F4 29 A4 4E 79 C3 46 58 05. That certificate expired in mid-2015 and its chain is now uniformly flagged as either time-invalid or explicitly revoked, yet the signature block is still stamped across every member of the set.

    #code-signingcertificateabuse#OptimizerPro#SpeedingUpMyPC#adware/PUP#typosquatting#Snowglobe#Babar#AnimalFarm
    ActorsSnowglobe · Animal FarmIOCf5 · i0 · d3 · u3MITRE44RegionsDE
  • FILEMembersJul 30, 2026, 13:44 (UTC+9)

    Four Shell Companies, One DigiCert Root: China Adware's Cert-Hopping Scheme

    Fifteen Windows installers branded as GPU tuners, file-recycling tools and browser guards share a single, less advertised trait: whichever shell company's name appears on the digital signature, the trust chain underneath always resolves to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root. Over roughly a year and a half, four distinct Chinese signing identities — 成都奇鲁科技有限公司, 天津中思明达科技有限公司, 天津立方星球文化传媒有限公司 and 天津星聚时代科技有限公司 — have taken turns wearing that same trusted…

    #code-signingabuse#certificaterotation#adware#PUPdistribution#ChinaTelecominfrastructure#DigiCert#domainfronting#supplychaintrust
    IOCf15 · i4 · d6 · u6MITRE12IndustriesTelecommunications
  • APTMembersJul 30, 2026, 13:33 (UTC+9)

    Two Chengdu Shell Certificates Keep an Adware Pipeline Signed for Eight Months

    Twelve Win32 binaries pulled from a single indicator set trace back to just two corporate code-signing identities — both registered in Chengdu, both chained to a valid DigiCert Trusted G4 root — and both still actively signing new builds of the same PC-optimizer adware lineage as of June 2026. Rather than a single malicious drop, what emerges is a release pipeline: eight files across two named signer cohorts, installed under at least seven different consumer utility brand names, moving through…

    #Ludashiadware#Chinad#code-signingcertificateabuse#Chengdu#DigiCert#PUAdistribution#masquerading#TLScertificatereuse
    ActorsFIN6 · Skeleton SpiderIOCf23 · i7 · d0 · u1MITRE11IndustriesWholesale
  • C&CMembersJul 30, 2026, 05:42 (UTC+9)

    One Reused Certificate Signs 20 Files in Wubi Input Adware Suite

    Twenty separate executables and DLLs packaged as components of "万能五笔输入法" — the Universal Wubi Input Method, a Chinese-language input tool — all carry the identical Authenticode signature from "Shanghai Oriental Webcasting Co. Ltd.," chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, with the exact same certificate serial number (0B 03 D3 41 0E 57 67 8D F3 FC A1 3A 38 44 3E 84) stamped across every file.

    #adware.softcnapp#code-signingabuse#Wubiinputmethod#DigiCertcertificatereuse#ChinanetCDNinfrastructure#PUAbundler#sandboxevasion#misattributedmalwarefamily
    IOCf39 · i9 · d0 · u0MITRE10
  • APTMembersJul 29, 2026, 14:14 (UTC+9)

    7-Zip Wrapper Hides Decade-Old KMS Activation Cracker

    Four Windows hacktools submitted to detection engines between 2016 and 2019 all trace back to the same cracking-tool lineage — kmsauto, autokms, kmsactivator, hackkms — the commodity ecosystem that has quietly sustained pirated Windows and Office activation for the better part of a decade. The most newsworthy fact in this cluster isn't who built it.

    #kmsauto#autokms#kmsactivator#hackkms#masquerading#anti-sandboxevasion#Ratiborus#piratedsoftware
    ActorsAPT27 · TEMP.HippoIOCf4 · i0 · d0 · u0MITRE16IndustriesAgriculture · Commercial Services · Education & Research
  • C&CMembersJul 29, 2026, 13:43 (UTC+9)

    Fake Bright Data Signature Cloaks PBot Stealer in Update Lure

    A Bright Data Ltd code-signing certificate — issued through DigiCert's Trusted G4 chain and still inside its 2025~2027 validity window — is authenticating a binary that a sandbox flags outright as the PBot stealer. The file, shipped internally as net_updater.exe, drops into install paths named "DriverHub" and "Bright VPN" [T1036.005], borrowing the visual language of a legitimate residential-proxy SDK to get past the trust checks that a valid signature is supposed to guarantee [T1553.002].

    #PBotstealer#code-signingabuse#BrightData#transportationsector#C2infrastructure#PUAmasquerade#.NETpacker#DigiCertcertificate
    IOCf49 · i4 · d10 · u0MITRE6IndustriesTransportation
  • APTMembersJul 29, 2026, 13:35 (UTC+9)

    Nine-Megabyte SFX Archive Bundles Five Crimeware Families Under Lazarus Label

    A 9.8MB self-extracting 7-Zip archive named 7zS.sfx.exe sits at the center of a file set nominally filed under the Lazarus Group label — but the malware riding inside it has nothing to do with bespoke espionage tooling. The archive, submitted alongside a matching overlay-carrying binary called setup_install.exe on 2022-06-05, carries seven named YARA hits, including Windows_API_Function, INDICATOR_EXE_Packed_ASPack, MALWARE_Win_DLInjector03, INDICATOR_EXE_Packed_VMProtect, AutoIT_Compiled, and…

    #LazarusGroup#RedlineStealer#SmokeLoader#Socelars#Fabookie#SFXarchivedelivery#commoditycrimeware#credentialtheft
    ActorsLazarus Group · Hastati GroupIOCf20 · i1 · d10 · u10MITRE8RegionsBR
  • APTMembersJul 29, 2026, 05:36 (UTC+9)

    Packing, Not Espionage, Explains 2017 'Barium' Adware Cluster

    Nine files in this indicator set carry an identical F-PROT packer signature and land at 0/60 to 5/72 on VirusTotal — yet five unpacked DLLs bearing the exact same filenames score 38/77 to 55/77 against the same engine pool. That gap is the actual story here, not a novel exploit or a freshly built implant: it is packing [T1027], cleanly isolated as the mechanism doing the evasion work, while the underlying code stays identical.

    #Fireball#Elexadware#PassCV#Barium#packingevasion#CloudFrontabuse#masquerading#commodityadware
    ActorsBarium · Wicked SpiderIOCf34 · i0 · d8 · u0MITRE44RegionsRO
  • APTMembersJul 28, 2026, 21:35 (UTC+9)

    KMS Crack Tool's Twin Binaries Hide Defender-Killer, Konni YARA Hits

    Two Windows binaries branded as a routine Microsoft-activation "crack" — one compiled for 32-bit systems, one for 64-bit — share an identical structural hash, reuse the exact same code-signing certificate, and both carry a built-in routine to switch off Windows Defender. That alone would be a tidy defense-evasion case study.

    #GamaredonGroup#Konni#WinDivert#code-signingabuse#WindowsDefenderevasion#KMScracktools#UPXpacking#anti-sandboxtechniques
    ActorsGamaredon Group · CTIGIOCf4 · i0 · d3 · u0MITRE36RegionsAR · BR · CI · COIndustriesConstruction · Consulting · Government
  • C&CMembersJul 28, 2026, 13:43 (UTC+9)

    One Chinese Signing Cert Underwrites Nine Adware Payloads

    A single Chinese code-signing identity has quietly underwritten an entire adware production line. Nine distinct Windows binaries — a mix of EXEs and DLLs distributed under two different "utility" brand names — all carry the identical certificate chain: 沧州句号网络科技有限公司, chained through GlobalSign GCC R45 CodeSigning CA 2020, GlobalSign Code Signing Root R45, and GlobalSign Root CA - R3.

    #code-signingabuse#adwarebundler#GlobalSigncertificate#ChinaUnicomhosting#masqueradingT1036.005#sandboxevasion#PUA-as-a-service#SaltySpiderattribution
    ActorsSalty Spider · KuKuIOCf11 · i4 · d3 · u1MITRE11
  • APTMembersJul 28, 2026, 13:34 (UTC+9)

    Broken 'Not Time Valid' Certificates Still Signing VPN Trojans

    Two unrelated commercial code-signing chains — one issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED through GlobalSign's EV pipeline, the other to INNOVATIVE CONNECTING PTE. LIMITED through DigiCert — are each producing a small, active cluster of VPN- and proxy-branded trojans whose leaf certificates carry the identical defect: "This certificate or one of the certificates in the certificate chain is not time valid." Neither cluster has stopped signing because of it.

    #code-signingabuse#WireVPN#VPNMaster#BrightData#PBotstealer#proxyware#certificatemisuse#TLSinfrastructure
    ActorsCactus · Cactus Ransomware GroupIOCf48 · i16 · d36 · u8MITRE18
  • FILEPublicJul 28, 2026, 05:47 (UTC+9)

    Shared Imphash Links Pirated Keygen Trojan to Signed 2026 Installer

    A single import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the thread connecting two very different-looking files: a widely pirated 2024 keygen trojan detected by 45 of 75 engines on VirusTotal, and a pair of 2026 binaries carrying a valid, unexpired code-signing certificate from a company called YAMICSOFT SOLUTIONS LIMITED.

    #imphashpivoting#code-signingabuse#AgentTesla#piratedsoftwarelure#YAMICSOFTSOLUTIONSLIMITED#TA505#detectionevasion#commoditymalware
    ActorsTA505 · Hive0065IOCf52 · i0 · d0 · u0MITRE10RegionsAT · AU · BE · BOIndustriesTechnology
  • C&CMembersJul 28, 2026, 05:37 (UTC+9)

    Fake uTorrent Installer Uses Malformed Signature to Hide Decade-Old Adware

    A Windows installer branded as uTorrent build 331 carries an Authenticode signature that fails validation outright — VirusTotal's own signing verdict states plainly that "the digital signature of the object is malformed," pointing analysts to the decade-old Microsoft security bulletin MS13-098 that documented exactly this class of forgeable signature block.

    #DealPly#InstallCore#uTorrent#adware#codesigningabuse#pay-per-install#downloadredirector#AzionCDN
    IOCf8 · i2 · d3 · u2MITRE34RegionsBRIndustriesSupport Services
  • C&CMembersJul 27, 2026, 05:36 (UTC+9)

    UnionPay-Named TLS Certificate Found Reused Across Three Chinese ISPs

    A single TLS certificate presenting the subject line `*.unionpayintl.com is now live on three IP addresses spread across three separate Chinese autonomous systems — 61.160.230.232 on AS140293 (CHINATELECOM Jiangsu province Changzhou 5G network), 58.216.102.31 on AS134769 (ChinaNet Jiangsu Changzhou Liyang IDC network), and 218.92.141.107 on AS4134 (Chinanet).

    #Ludashi#unwantedx#adware#codesigningcertificateabuse#TLScertificatereuse#PUAbundling#ChineseISPs#DigiCert
    ActorsFIN6 · Skeleton SpiderIOCf29 · i5 · d3 · u2MITRE38IndustriesEducation & Research · Wholesale
2
Of11
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.