C&CMembersAug 9, 2026, 10:54 (UTC+9)Chinese Adware Ring Reuses Certs to Spoof UnionPay and Huawei
Every piece of command infrastructure in this record — all seven IP addresses tied to the cluster — sits on a single Chinese carrier backbone, AS4837, CHINA UNICOM China169 Backbone. That alone would be a footnote for China-facing infrastructure. What makes it a story is what those IPs present to anyone who connects to them: two separate, duplicated TLS certificates, each spoofing a different trusted brand.
#code-signingabuse#TLScertificatespoofing#UnionPayimpersonation#HuaweiAppGalleryspoofing#ChinaUnicomAS4837#ludashiadware#anti-analysistechniques#PUAdistributionIOCf28 · i7 · d0 · u0MITRE14
APTMembersAug 9, 2026, 10:45 (UTC+9)Old RemCom Hacktool Masks a Clean-Scoring WinSW Impostor
A remote-command-execution hacktool compiled on 2012-08-09 is still being resubmitted under randomized filenames as recently as July 2026, flagged by 46 of 75 engines and matched by three named YARA rules — and sitting in the same indicator set is a 16.8-megabyte binary posing as the open-source WinSW Windows Service Wrapper that clears every one of 77 antivirus engines outright.
#RemCom#WinSWimpersonation#lateralmovement#bulletproofhosting#Proton66#Flyservers#njRAT#CactusransomwaregroupActorsCactus · Cactus Ransomware GroupIOCf2 · i13 · d0 · u0MITRE20
FILEMembersAug 9, 2026, 01:56 (UTC+9)Fake Root CA Signs Pirated KMS Activation Tools
Four Windows activation cracks distributed under the KMSpico and AutoKMS names carry an identical code-signing chain — but the authority that issued it isn't Sectigo, DigiCert, or any of the trust roots Windows ships with. It's "@ByELDI Certificate Authority," a self-manufactured root the operators built themselves, and every certificate under it fails Windows' own validation check.
#KMSpico#AutoKMS#codesigningabuse#self-signedcertificate#piratedsoftware#dynamicDNS#anti-analysistechniques#PatchworkActorsPatchwork · ChinastratsIOCf14 · i1 · d1 · u1MITRE51
APTMembersAug 9, 2026, 01:46 (UTC+9)A Disposable AWS Front and a CDN Wildcard Are the Real Story, Not the File
Two pieces of infrastructure — a beacon domain delegated through Amazon's own nameservers and a CDN-fronted IP wearing someone else's wildcard certificate — carry far more evidential weight in this record than the single file attached to it. The domain, wb.sleevesbarbing.com, resolves through eight rotating A-records behind AWS Route53 delegation and serves six URLs that all follow the identical templated path /mtn/130079/<32-character-hash>.<epoch-timestamp>.000.
#AWSRoute53delegation#CDNwildcardcertificate#AdvancedIPScanner#Famatechcodesigning#Edgenextinfrastructure#telecomsectortargeting#disposableC2domain#expiredcertificatechainActorsLockbit GangIOCf1 · i1 · d1 · u6MITRE4IndustriesTelecommunications
FILEMembersAug 9, 2026, 00:27 (UTC+9)One Code-Signing Certificate Covers 14 WaveBrowser Bundleware Files
A single leaf certificate — serial 09 D7 7A 45 C1 C0 97 55 AE 3E 7A 51 53 98 3C 03, issued to "Wavesor Software (Eightpoint Technologies Ltd. SEZC)" under the DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 chain — signs all fourteen core binaries CTX Team has catalogued for a browser-and-updater bundle marketed as WaveBrowser and its companion SWUpdater service.
#codesigningcertificateabuse#bundleware#WaveBrowser#SWUpdater#PUA/adware#sandboxevasion#Authenticodetrust#misattributionActorsAPT28 · StrontiumIOCf16 · i1 · d0 · u0MITRE9IndustriesEducation & Research
FILEPublicAug 8, 2026, 23:59 (UTC+9)Signed Process Hacker Driver Now Anchors a Four-Stage Attack Chain
A signed kernel driver that Microsoft's own trust chain still vouches for is quietly doing double duty as a privilege-escalation primitive, and it is not travelling alone. The newest indicators added to a long-tracked Process Hacker 2 file set — both the x86 and x64 builds of kprocesshacker.sys (0f97f6d53fff…, 70211a3f9037…) — fire the LOLDrivers-catalogued rule PUA_VULN_Driver_Wj_Kprocesshacker_7021 despite carrying a fully valid DigiCert code-signing chain.
#ProcessHacker#BYOVD#kprocesshacker.sys#LOLDrivers#NirSoft#credentialtheft#signedmalware#kernelprivilegeescalationActorsRoyal Ransomware · Team OneIOCf35 · i0 · d0 · u0IndustriesGovernment
APTMembersAug 8, 2026, 23:04 (UTC+9)Windows Defender-Killer Tool Folded Into XRed RAT Dropper
A commodity tool built to switch off Windows Defender with one click has turned up inside the build of a remote-access-trojan dropper — not dropped alongside it, but sharing the same crowdsourced YARA signature. The standalone hacktool, tracked publicly as DefenderControl and carried in this set as 1ef6c1a4dfdc39b63bfe650ca81ab89510de6c0d3d7c608ac5be80033e559326, and a Synaptics-driver-themed dropper that sandboxing names as the XRed RAT,…
#GorgonGroup#Subaat#XRedRAT#DefenderControl#HongKongtechnologysector#dynamicDNSabuse#masqueradetechnique#espionageActorsGorgon Group · SubaatIOCf15 · i1 · d0 · u0MITRE29RegionsHKIndustriesTechnology
C&CMembersAug 8, 2026, 20:44 (UTC+9)Valid Bright Data Signature Found on EarnApp Installers Flagged as PBot Stealer
Four Windows installers branded as EarnApp — the passive-income tool that pays users to resell idle bandwidth through Bright Data's proxy network — carry a fully valid Bright Data Ltd code-signing chain from DigiCert, and two of them are independently flagged by a sandbox as the "PBot" stealer family. That combination is the story here, not because a certificate was forged or revoked, but because it wasn't.
#EarnApp#BrightData#PBotstealer#code-signingabuse#DigiCert#supply-chaintrustabuse#proxyware#bandwidth-sharingmalwareIOCf69 · i22 · d98 · u9MITRE4IndustriesCommercial Services
FILEPublicAug 8, 2026, 19:48 (UTC+9)One Trojan Sample Shows Full Evasion Playbook, No Campaign in Sight
A Win32 executable currently flagged by 61 of 76 antivirus engines packs a textbook sandbox-evasion triad — checking for an attached debugger, reading the CPU clock directly, and inspecting the CPU model string — into a single unsigned dropper that has circulated under at least four unrelated decoy filenames since 2016. What makes the sample newsworthy is not a hosting cluster or a signing certificate; there is neither.
#trojan.python/fkuk#stitchmalwarefamily#sandboxevasion#WMIdiscovery#HolyWater#StormCloud#persistencetechniques#lurefilenamesActorsHolyWater · Storm CloudIOCf1 · i0 · d0 · u0IndustriesEducation & Research
C&CMembersAug 8, 2026, 19:39 (UTC+9)Fake UnionPay TLS Certificate Ties Together 19 Chinese Adware Hosts
Nineteen IP addresses scattered across five or more distinct Chinese ISPs — China Unicom's China169 backbone, three separate China Mobile autonomous systems, and a scatter of regional China Telecom blocks — all present the identical TLS certificate when a browser connects to them. The subject line reads *.unionpayintl.com, organisation "UnionPay International Co., Ltd.," issued by DigiCert's Basic OV G2 TLS CA.
#UnionPayimpersonation#wildcardTLScertificate#Ludashi#Chinad#PolarWind#codesigningabuse#APT23#adwaredistributioninfrastructureActorsAPT23 · KeyBoyIOCf17 · i23 · d2 · u0MITRE7
APTMembersAug 8, 2026, 19:30 (UTC+9)Valid Code Signatures Mask PBot Stealer in VPN/Proxy Installers
A Windows installer branded as Bright Data's residential-proxy SDK carries a complete, unbroken DigiCert code-signing chain — and still returns a sandbox verdict naming the PBot stealer classification. Across ten files reviewed by CTX Team, three separate code-signing identities — Bright Data Ltd, WEILAI NETWORK TECHNOLOGY CO., LIMITED, and INNOVATIVE CONNECTING PTE.
#PBotstealer#code-signingabuse#proxyware#BrightData/Luminati#WireVPN#VPNMaster#DigiCert#PUAActorsEmotet Group · TA542IOCf15 · i36 · d51 · u10MITRE22
C&CMembersAug 8, 2026, 14:23 (UTC+9)One Chinese Certificate Signed Nine Months of Ludashi Adware Builds
The most durable piece of infrastructure behind a sprawling family of Chinese system-utility adware is not a server or a domain — it is a single code-signing certificate. Eight of nine binaries examined in this cluster carry an identical signer chain: 成都奇鲁科技有限公司, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert's root, with certificate serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98.
#Ludashiadware#code-signingcertificateabuse#ChinaD#UnwantedX#wildcardTLScertificate#China-basedinfrastructure#adwareC2#PUAdistributionActorsFIN6 · Skeleton SpiderIOCf9 · i2 · d4 · u3MITRE11
APTMembersAug 7, 2026, 06:05 (UTC+9)Old Macro-to-PowerShell Emotet Chain Still Fools Every Sandbox
A macro-laced Word document circulating against United States education and research targets is producing a rare thing in modern detection telemetry: unanimous agreement. All three sandboxes that processed the sample — C2AE, ReaQta-Hive, and BitDam ATP — return a "malicious" verdict, and 43 of 75 antivirus engines flag the file outright.
#Emotet#TA542#macromalware#PowerShelldownloader#educationsector#masquerading#Let'sEncryptcertificates#loader-for-hireActorsEmotet Group · TA542IOCf3 · i1 · d2 · u5RegionsUSIndustriesEducation & Research
C&CMembersAug 6, 2026, 22:12 (UTC+9)C2 Cluster Adds 9 IPs, 20 Domains — Just 5 New Files
Nine new IP addresses and twenty new domains have surfaced around a C2-server cluster CTX Team has been tracking since earlier coverage of a campaign built on trojanized VPN and proxy installers ("Two Vendor Signatures, One Stealer"). Only five new files joined the set in the same window. That lopsided ratio is itself the story: the operators are not retooling their malware, they are aggressively provisioning and rotating the network fabric that fronts it.
#C2infrastructure#trojanizedinstallers#WireVPN#BrightDataimpersonation#certificatereuse#SpacePirates#Cactus#disposableinfrastructureActorsSpace Pirates · WebwormIOCf14 · i21 · d47 · u6MITRE16
C&CMembersAug 5, 2026, 22:13 (UTC+9)Batch-Signed Adware Beats AV Detection, Fools Every Sandbox
A code-signing certificate issued to a company called Shenzhen Kaixin Kangaroo Technology Co., Ltd. was used to sign eight different executables and DLLs — all in the same eight-minute window on March 20, 2024. A separate certificate, issued this time to Shanghai Oriental Webcasting Co. Ltd., produced the same pattern two months later: seven of eight files signed within a single minute on May 29, 2024.
#code-signingcertificateabuse#adware#PUA#GoodZip#WanNengWBInput#APT27#SaltySpider#ChinaCDNinfrastructureActorsAPT27 · TEMP.HippoIOCf30 · i14 · d1 · u1MITRE24
APTMembersAug 5, 2026, 22:04 (UTC+9)Wizard Spider Kit Adds Stealer-to-Downloader Handoff, C2 Unchanged
The kit CTX Team has tracked under this cluster just picked up a matched pair of new files, and they slot together like a delivery chain missing its middle link. A stealc-tagged dropper — carried under the path %APPDATA%\crkhost.exe and flagged malicious by 55 of 76 engines — and a downloader dressed as a Windows service process, taskhostw.exe (also seen as WinUpdateHelper.exe, 46/76 detections), both first appeared within a 24-hour window in early May and both share a single YARA signature:…
#WizardSpider#Stealc#credentialtheft#vulnerabledriverabuse#hostsfiletampering#certificateimpersonation#AS214351#commandandcontrolinfrastructureActorsWizard Spider · Grim SpiderIOCf5 · i3 · d0 · u6MITRE25RegionsJOIndustriesFood & Beverages
FILEMembersAug 5, 2026, 11:49 (UTC+9)Pirated Windows Activator Bundle Hides Shared Base64 Execution Trick
A "Microsoft Activation Scripts" archive built to bypass Windows and Office licensing is now doubling as a delivery mechanism for base64-encoded PowerShell payloads — and the same authoring fingerprint shows up in two structurally different file types inside the same drop. Eight of nine files tied to this indicator set carry file paths referencing "MAS/Separate-Files-Version" or "MAS/All-In-One-Version-KL," all first appearing within a 48-hour window between July 4 and July 6, 2026.
#TA505#rockloader#hacktool.autokms#hacktool.kmsauto#base64PowerShellexecution#KMSactivationpiracy#WindowsOfficelicensing#.winTLDDNScallbackActorsTA505 · Hive0065IOCf10 · i1 · d0 · u0MITRE13
C&CMembersAug 5, 2026, 11:41 (UTC+9)Two Vendor Signatures, One Stealer: VPN Installers Abuse Trust Chains
Three files circulating under VPN branding this year carry a code-signing chain that VirusTotal's own signer inspection flags as broken. The signer field reads "WEILAI NETWORK TECHNOLOGY CO., LIMITED," countersigned through GlobalSign GCC R45 EV CodeSigning CA 2020, and every one of the three samples' signer-details blocks returns the same line: "This certificate or one of the certificates in the certificate chain is not time valid." That should be a hard stop for any endpoint relying on…
#code-signingabuse#PBotstealer#BrightData#WEILAINETWORKTECHNOLOGY#VPNinstallertrojan#fast-fluxhosting#Let'sEncryptabuse#SpacePiratesActorsSpace Pirates · WebwormIOCf9 · i15 · d27 · u3MITRE17
APTMembersAug 5, 2026, 05:34 (UTC+9)Fake YCleaner Hides PowerShell Fetch Loop Behind Spoofed AV Certificate
A "system cleaner" branded YCleaner wraps a multi-stage dropper chain that leans on a spoofed antivirus-vendor certificate and a single PowerShell-invoked downloader signature reused across three separate binaries — and stages its final payload inside a ZIP archive that, as of this writing, zero of 77 scanning engines flag as malicious. The domain feeding the chain, adobehelp.net, carries a nameserver record that contradicts its own WHOIS listing.
#YCleaner#PowerShelldownloader#fakesystemcleaner#BlueBottle#adobehelp.net#code-signingspoofing#encryptedarchiveevasion#MalaysiaActorsBlueBottle · Opera1erIOCf16 · i0 · d1 · u2MITRE29RegionsMY
FILEMembersAug 4, 2026, 13:47 (UTC+9)Validly Signed uTorrent Installer Hides Trojan.Offercore
An executable calling itself utorrent_installer.exe carries a fully valid four-tier code-signing chain — BitTorrent Inc, chained up through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 to DigiCert Trusted Root G4 — and yet 18 of 76 engines still flag it as trojan.offercore/r783575. That combination is the story here: not a forged certificate, but a genuine one riding on top of a payload the security industry has learned to distrust.
#trojan.offercore#code-signingabuse#uTorrent#anti-sandboxevasion#CloudFrontinfrastructure#P2Ptrafficmimicry#adware/PUP#TLScertificatespoofingIOCf28 · i4 · d2 · u0MITRE48RegionsAD · AE · AL · AMIndustriesChemicals · Commercial Services · Construction
APTMembersAug 4, 2026, 05:33 (UTC+9)Donot Team Ties Three Domain Clusters via 89-Day Cert Cadence
Five domains, three registrars, three continents' worth of WHOIS geography, and not a single shared owner on paper — yet every one of them carries an identical 89-day Let's Encrypt certificate validity window. That convergence, surfaced across a Thai medical-software vendor's subdomain fleet, an AWS Route53-fronted delivery node registered through a Panama privacy proxy, and a decade-old Japanese domain flagged for compromise, is the strongest signal in this indicator set — stronger, in fact,…
#DonotTeam#APTC35#SectorE02#certificateprovisioning#spearphishing#healthcaretargeting#AWSRoute53abuse#domainhijackingActorsAPTC35 · Donot TeamIOCf7 · i0 · d5 · u15MITRE18IndustriesGovernment · Healthcare · Telecommunications
FILEMembersAug 3, 2026, 21:49 (UTC+9)Old Allaple Worm Label Reused on Adobe-Masquerading HTML Droppers
Three HTML files carrying VirusTotal's family label "trojan.allaple" — 1102b8a9933b2191f1b80bd9bc478f301536216332ddf2986d3ffc792474be3d, 7768dae586920feac88943b260caa4f9a26bd357603d81517431d38f5e026594, and eb333a956be00c99c0d2523fabbea40f08ce65f5120e2744a24a5fb3abbfa3b7 — were submitted between April and August 2024, and two of them stage themselves under file paths built to look like legitimate Adobe software.
#Allaple#HTMLdropper#masquerading#embeddedJavaScript#sandboxevasion#AT&Tinfrastructure#Germanresearchnetwork#malwarefamilyreuseIOCf33 · i34 · d0 · u0MITRE24RegionsUSIndustriesRetail
APTMembersAug 3, 2026, 21:35 (UTC+9)A Builder Stub That Outlived Four Different Malware Labels
Cybercrime taxonomies love clean boundaries — XWorm here, Amadey there, a "msilheracles" trojan somewhere else. But a set of Windows binaries CTX Team has been tracking, tagged in upstream telemetry to APT28-associated activity, shows how thin those labels can be. Four samples that public detection engines classify as four unrelated families — a 2024 XWorm loader, a 2023 Amadey downloader, and two "QCoin"-branded .NET binaries dating back to December 2017 — all carry the exact same import-table…
#APT28#XWorm#Amadey#DarkKomet#XRed#imphashreuse#timestomping#masqueradingActorsAPT28 · StrontiumIOCf35 · i7 · d2 · u6MITRE100
APTMembersAug 3, 2026, 13:34 (UTC+9)Fake reCAPTCHA Lure Tied to Dedicated Host via Certificate Match
A domain calling itself verifyrecapcha.info is not, in fact, a CAPTCHA. It is a phishing front end that mimics the verification interstitial Google uses to separate humans from bots, and it has been flagged by 19 of 91 security engines — a detection band that puts it firmly in known-bad territory even before the infrastructure underneath it is examined.
#Tortilla#phishinginfrastructure#fakereCAPTCHA#TLScertificatepivot#Cloudflarefronting#resellerhosting#espionage#PDR/DirectiASNActorsTortillaIOCf0 · i4 · d2 · u1MITRE10IndustriesArts & Entertainment
C&CMembersAug 3, 2026, 05:32 (UTC+9)APT28-Tagged Cluster Shows 89-Day Cert Pattern, No Malware
Three domains with nothing else in common — different registrars, different creation dates, different Let's Encrypt intermediates — share one oddly precise trait: certificates valid for exactly 89 days. ccu.to, swisscutterastronaut.com, and each-task.com were issued certificates by three separate Let's Encrypt intermediates (R13, YR2, and YE1, respectively), yet all three validity windows run to the same 89-day span.
#APT28#FancyBear#Let'sEncryptcertificates#certificatecloning#C2infrastructure#domainregistrationfraud#espionage#TencentCDNActorsAPT28 · StrontiumIOCf0 · i5 · d7 · u0MITRE4IndustriesContainers & Packaging
APTMembersAug 2, 2026, 21:35 (UTC+9)VPN Trojan Cluster Adds 10 IPs, 6 Domains, No New Malware
The latest pass through this VPN-and-proxy-trojan operation surfaces ten additional IP addresses and six additional domains — and not a single new malicious binary. That lopsided delta is itself the story. While the signed installers that anchor this campaign have sat unchanged for months, the network layer underneath them keeps expanding, and the clearest evidence of that expansion is a single TLS certificate serial, 363a6b88ee219be351b40934, now confirmed live on four separate hosts spread…
#VPNtrojan#proxymalware#certificateabuse#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTING#BrightData#China#PhilippinesActorsUAC-0063 · TAG-110IOCf35 · i21 · d15 · u4MITRE21IndustriesTechnology
FILEMembersAug 2, 2026, 05:49 (UTC+9)Fake Shipping Documents Deliver AgentTesla Stealer Under Five Packers
The payload doesn't look like malware when it lands in an inbox. It looks like a vessel particulars sheet — "MV TBN SHIP PARTICULARS.docx.exe," "SHIP PARTICULARS - MV OSTC01.xlsx.exe," "MV PACIFIC ENDEAVOR V2202 PARTICULARS I.docx.exe." Each of those alternate filenames belongs to the same 490KB Windows executable, a double-extension trick that hides an EXE behind a familiar Word or Excel icon — a lure built for whoever in a shipping or freight-forwarding chain is used to receiving cargo…
#AgentTesla#spear-phishing#maritimeshippinglure#double-extensionmalware#.NETobfuscation#SMTPexfiltration#APT29misattribution#commodityinfostealerActorsAPT29 · MinidionisIOCf9 · i0 · d2 · u0MITRE38
C&CMembersAug 2, 2026, 05:41 (UTC+9)Fake Baidu, Alibaba TLS Certs Mask Five-Year RAT Campaign
Ten IP addresses tied to a single threat-intelligence record show almost no malicious signal on their own — nine come back 0/91 on antivirus scanning, one scrapes a single flag at 1/91. Yet three of those IPs pair up with a twin elsewhere on the internet through an identical TLS certificate, and each pairing wildcards a domain the certificate's real owner has nothing to do with. Two Alibaba Cloud-registered addresses share one GlobalSign-issued certificate for .certfallback.com.
#XRedRAT#certificatereuse#TLSimpersonation#Baiduspoofing#AlibabaCloud#ChinaUnicom#APT28attribution#dynamicDNSC2ActorsAPT28 · StrontiumIOCf13 · i10 · d0 · u0MITRE40RegionsTW
APTMembersAug 2, 2026, 05:31 (UTC+9)Expired Certificates Keep Signing Trojanized VPN Installers
The most durable piece of tradecraft in this campaign isn't a novel loader or a clever injection technique — it's a pair of Authenticode certificates that have been technically invalid for months and are still being used to sign new builds. Two code-signing identities, WEILAI NETWORK TECHNOLOGY CO., LIMITED (chained through GlobalSign GCC R45 EV CodeSigning CA 2020) and INNOVATIVE CONNECTING PTE.
#code-signingabuse#certificatechainmanipulation#VPNtrojan#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTING#Philippinetelecominfrastructure#TLScertificatereuse#supply-chaincompromiseActorsUAC-0063 · TAG-110IOCf74 · i13 · d13 · u3MITRE22IndustriesTechnology
APTMembersAug 1, 2026, 21:36 (UTC+9)Adware Operator Re-Signs Same Stale Build Across Two CAs
A twelve-file Authenticode cohort tied to a Windows browser product called "OneBrowser" shows something unusual for a piece of adware: the operator kept re-signing the same eight-month-old executable under a fresh certificate every time the previous one lapsed. The pattern surfaces in a batch of files carrying the identical certificate serial 0E F9 0B 20 6A 1B 07 82 E0 D0 FD 33 88 24 EC 42, issued under a GoGetSSL G4 CS RSA4096 chain rooted in DigiCert, with Authenticode signing dates falling…
#OneBrowseradware#codesigningabuse#Authenticodecertificatechurn#PUAdistribution#APT28misattribution#WorkProductInc#browserhijacking#threatinteltaggingActorsAPT28 · StrontiumIOCf18 · i0 · d2 · u44MITRE8IndustriesTelecommunications
C&CMembersAug 1, 2026, 05:38 (UTC+9)EV Certificate Lets ORYON Adware Suite Slip Past Sandbox Scans
Four differently named Windows installers — AdvancedWindowsManager.exe, Windows Updater.exe, Installer_1.0.0.exe and an MSI package called e78a2.msi — carry the exact same code-signing chain: ORYON TECH LIMITED, chaining through Sectigo Public Code Signing CA EV R36 and Sectigo Public Code Signing Root R46, all signed at the identical timestamp of 08:36 AM on 04/23/2026. That precision is the story.
#ORYONTECHLIMITED#EVcodesigningabuse#microleavesadware#sandboxevasion#pay-per-install#Cloudflareredirectordomains#QuickFetchloader#PUPdistributionIOCf20 · i1 · d5 · u15MITRE22RegionsBE · CA · DZ · GBIndustriesRetail · Technology
FILEMembersJul 31, 2026, 21:52 (UTC+9)Revoked Certs and a 1992 Timestamp: A Hacktool Kit That Won't Die
The most striking fact in this 46-file batch isn't a new malware family — it's that the tools are old, freely available, and still working. Four driver and library builds of the open-source credential-dumping tool mimikatz, including the file hashed bd177792a573f81a96c7ca9833ab7090eb8a5ea0491d1b1381efc2a5ac3f54b0, continue to carry Benjamin Delpy's original code-signing chain years after the underlying certificates were explicitly revoked by their issuers.
#mimikatz#Neshta#NirSoft#revokedcode-signingcertificates#credentialdumping#dual-usetools#LSASS#imphashActorsRoyal Ransomware · Team OneIOCf46 · i0 · d0 · u0MITRE19
APTMembersJul 31, 2026, 21:36 (UTC+9)Signed Chinese Input-Method Suite Hides IcedID-Flagged Loader
Four Windows binaries branded as 万能五笔输入法 — a legitimate Chinese Wubi input-method suite — carry an identical Extended Validation code-signing certificate, the same build timestamp, and, in two cases, a payload signature tied to the IcedID malware family, even though the sandboxes that examined them returned a clean verdict. The pairing of trusted EV signing with a static loader-kit fingerprint that slips past dynamic analysis is the sharpest signal in a nine-file, nine-IP cluster CTX Team has…
#APT27#IcedID#code-signingabuse#BYOVD#kerneldriver#CDNimpersonation#China#supplychaintrojanActorsAPT27 · TEMP.HippoIOCf9 · i9 · d0 · u0MITRE11
C&CMembersJul 31, 2026, 13:43 (UTC+9)Two 'Rival' Chinese Software Brands Share One Signing Chain
Fourteen signed Win32 binaries surfaced carrying the trusted names of two separate Chinese software vendors — a "万能五笔输入法" input-method utility from Shanghai Oriental Webcasting Co. Ltd. and a "2345看图王" photo-viewer suite from Shanghai 2345 Mobile Technology Co., Ltd. — yet both cohorts chain to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root, and a single YARA rule fires across samples signed by each.
#adware#codesigningabuse#DigiCert#China#CDNinfrastructure#YARAfingerprint#Group123/APT37misattribution#SalitymisattributionActorsGroup123 · Venus 121IOCf14 · i6 · d0 · u0MITRE28
APTMembersJul 31, 2026, 13:33 (UTC+9)Decade-Spanning Cert Cohort Exposes Cactus's Standing Provisioning Pipeline
Four domains that share nothing else — not a registrar, not a top-level domain, not even a decade of age — converge on the same certificate authority, the same 89-day validity window, and an issuance timeline packed into roughly two months. 5.tipsy.co.za has been registered since 2013; presidencycollege.in surfaced in 2024 and sat dormant until this year.
#Cactus#YR1certificatecohort#Gname.com#DigiCertG4signingchain#PBotstealer#domaingenerationalgorithm#phishingdomainreactivation#telecommunicationssectorActorsCactus · Cactus Ransomware GroupIOCf23 · i3 · d9 · u0IndustriesTelecommunications
C&CMembersJul 31, 2026, 05:44 (UTC+9)Shared Certificates, Not Payloads, Tie Five Emotet-Linked Domains
Five domains and a single Hostinger-hosted IP address form a hosting cluster that looks less like purpose-built command infrastructure and more like a disposable inventory kept in circulation for years. Across the set, two distinct certificate-issuer cohorts and a shared nameserver pairing tie the nodes together with far more precision than anything the lone piece of file telemetry in this record can offer. The strongest signal here isn't a payload — it's the paperwork.
#Emotet#TA542#C2infrastructure#Let'sEncryptcertificates#domainreuse#Hostinger#educationsector#macrodownloaderActorsEmotet Group · TA542IOCf3 · i1 · d5 · u2RegionsUSIndustriesEducation & Research
APTMembersJul 31, 2026, 05:34 (UTC+9)A Revoked 2014 Certificate Still Signs the Same Adware Family
Four binaries tied to a Windows "PC optimization" installer chain — an EXE, its setup-extraction temp copy, and two helper DLLs — all carry the identical code-signing leaf certificate issued to "PC Utilities Software Limited," serial 00 CF 20 ED FB 9E 9D 56 F4 29 A4 4E 79 C3 46 58 05. That certificate expired in mid-2015 and its chain is now uniformly flagged as either time-invalid or explicitly revoked, yet the signature block is still stamped across every member of the set.
#code-signingcertificateabuse#OptimizerPro#SpeedingUpMyPC#adware/PUP#typosquatting#Snowglobe#Babar#AnimalFarmActorsSnowglobe · Animal FarmIOCf5 · i0 · d3 · u3MITRE44RegionsDE
FILEMembersJul 30, 2026, 13:44 (UTC+9)Four Shell Companies, One DigiCert Root: China Adware's Cert-Hopping Scheme
Fifteen Windows installers branded as GPU tuners, file-recycling tools and browser guards share a single, less advertised trait: whichever shell company's name appears on the digital signature, the trust chain underneath always resolves to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root. Over roughly a year and a half, four distinct Chinese signing identities — 成都奇鲁科技有限公司, 天津中思明达科技有限公司, 天津立方星球文化传媒有限公司 and 天津星聚时代科技有限公司 — have taken turns wearing that same trusted…
#code-signingabuse#certificaterotation#adware#PUPdistribution#ChinaTelecominfrastructure#DigiCert#domainfronting#supplychaintrustIOCf15 · i4 · d6 · u6MITRE12IndustriesTelecommunications
APTMembersJul 30, 2026, 13:33 (UTC+9)Two Chengdu Shell Certificates Keep an Adware Pipeline Signed for Eight Months
Twelve Win32 binaries pulled from a single indicator set trace back to just two corporate code-signing identities — both registered in Chengdu, both chained to a valid DigiCert Trusted G4 root — and both still actively signing new builds of the same PC-optimizer adware lineage as of June 2026. Rather than a single malicious drop, what emerges is a release pipeline: eight files across two named signer cohorts, installed under at least seven different consumer utility brand names, moving through…
#Ludashiadware#Chinad#code-signingcertificateabuse#Chengdu#DigiCert#PUAdistribution#masquerading#TLScertificatereuseActorsFIN6 · Skeleton SpiderIOCf23 · i7 · d0 · u1MITRE11IndustriesWholesale
C&CMembersJul 30, 2026, 05:42 (UTC+9)One Reused Certificate Signs 20 Files in Wubi Input Adware Suite
Twenty separate executables and DLLs packaged as components of "万能五笔输入法" — the Universal Wubi Input Method, a Chinese-language input tool — all carry the identical Authenticode signature from "Shanghai Oriental Webcasting Co. Ltd.," chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, with the exact same certificate serial number (0B 03 D3 41 0E 57 67 8D F3 FC A1 3A 38 44 3E 84) stamped across every file.
#adware.softcnapp#code-signingabuse#Wubiinputmethod#DigiCertcertificatereuse#ChinanetCDNinfrastructure#PUAbundler#sandboxevasion#misattributedmalwarefamilyIOCf39 · i9 · d0 · u0MITRE10
APTMembersJul 29, 2026, 14:14 (UTC+9)7-Zip Wrapper Hides Decade-Old KMS Activation Cracker
Four Windows hacktools submitted to detection engines between 2016 and 2019 all trace back to the same cracking-tool lineage — kmsauto, autokms, kmsactivator, hackkms — the commodity ecosystem that has quietly sustained pirated Windows and Office activation for the better part of a decade. The most newsworthy fact in this cluster isn't who built it.
#kmsauto#autokms#kmsactivator#hackkms#masquerading#anti-sandboxevasion#Ratiborus#piratedsoftwareActorsAPT27 · TEMP.HippoIOCf4 · i0 · d0 · u0MITRE16IndustriesAgriculture · Commercial Services · Education & Research
C&CMembersJul 29, 2026, 13:43 (UTC+9)Fake Bright Data Signature Cloaks PBot Stealer in Update Lure
A Bright Data Ltd code-signing certificate — issued through DigiCert's Trusted G4 chain and still inside its 2025~2027 validity window — is authenticating a binary that a sandbox flags outright as the PBot stealer. The file, shipped internally as net_updater.exe, drops into install paths named "DriverHub" and "Bright VPN" [T1036.005], borrowing the visual language of a legitimate residential-proxy SDK to get past the trust checks that a valid signature is supposed to guarantee [T1553.002].
#PBotstealer#code-signingabuse#BrightData#transportationsector#C2infrastructure#PUAmasquerade#.NETpacker#DigiCertcertificateIOCf49 · i4 · d10 · u0MITRE6IndustriesTransportation
APTMembersJul 29, 2026, 13:35 (UTC+9)Nine-Megabyte SFX Archive Bundles Five Crimeware Families Under Lazarus Label
A 9.8MB self-extracting 7-Zip archive named 7zS.sfx.exe sits at the center of a file set nominally filed under the Lazarus Group label — but the malware riding inside it has nothing to do with bespoke espionage tooling. The archive, submitted alongside a matching overlay-carrying binary called setup_install.exe on 2022-06-05, carries seven named YARA hits, including Windows_API_Function, INDICATOR_EXE_Packed_ASPack, MALWARE_Win_DLInjector03, INDICATOR_EXE_Packed_VMProtect, AutoIT_Compiled, and…
#LazarusGroup#RedlineStealer#SmokeLoader#Socelars#Fabookie#SFXarchivedelivery#commoditycrimeware#credentialtheftActorsLazarus Group · Hastati GroupIOCf20 · i1 · d10 · u10MITRE8RegionsBR
APTMembersJul 29, 2026, 05:36 (UTC+9)Packing, Not Espionage, Explains 2017 'Barium' Adware Cluster
Nine files in this indicator set carry an identical F-PROT packer signature and land at 0/60 to 5/72 on VirusTotal — yet five unpacked DLLs bearing the exact same filenames score 38/77 to 55/77 against the same engine pool. That gap is the actual story here, not a novel exploit or a freshly built implant: it is packing [T1027], cleanly isolated as the mechanism doing the evasion work, while the underlying code stays identical.
#Fireball#Elexadware#PassCV#Barium#packingevasion#CloudFrontabuse#masquerading#commodityadwareActorsBarium · Wicked SpiderIOCf34 · i0 · d8 · u0MITRE44RegionsRO
APTMembersJul 28, 2026, 21:35 (UTC+9)KMS Crack Tool's Twin Binaries Hide Defender-Killer, Konni YARA Hits
Two Windows binaries branded as a routine Microsoft-activation "crack" — one compiled for 32-bit systems, one for 64-bit — share an identical structural hash, reuse the exact same code-signing certificate, and both carry a built-in routine to switch off Windows Defender. That alone would be a tidy defense-evasion case study.
#GamaredonGroup#Konni#WinDivert#code-signingabuse#WindowsDefenderevasion#KMScracktools#UPXpacking#anti-sandboxtechniquesActorsGamaredon Group · CTIGIOCf4 · i0 · d3 · u0MITRE36RegionsAR · BR · CI · COIndustriesConstruction · Consulting · Government
C&CMembersJul 28, 2026, 13:43 (UTC+9)One Chinese Signing Cert Underwrites Nine Adware Payloads
A single Chinese code-signing identity has quietly underwritten an entire adware production line. Nine distinct Windows binaries — a mix of EXEs and DLLs distributed under two different "utility" brand names — all carry the identical certificate chain: 沧州句号网络科技有限公司, chained through GlobalSign GCC R45 CodeSigning CA 2020, GlobalSign Code Signing Root R45, and GlobalSign Root CA - R3.
#code-signingabuse#adwarebundler#GlobalSigncertificate#ChinaUnicomhosting#masqueradingT1036.005#sandboxevasion#PUA-as-a-service#SaltySpiderattributionActorsSalty Spider · KuKuIOCf11 · i4 · d3 · u1MITRE11
APTMembersJul 28, 2026, 13:34 (UTC+9)Broken 'Not Time Valid' Certificates Still Signing VPN Trojans
Two unrelated commercial code-signing chains — one issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED through GlobalSign's EV pipeline, the other to INNOVATIVE CONNECTING PTE. LIMITED through DigiCert — are each producing a small, active cluster of VPN- and proxy-branded trojans whose leaf certificates carry the identical defect: "This certificate or one of the certificates in the certificate chain is not time valid." Neither cluster has stopped signing because of it.
#code-signingabuse#WireVPN#VPNMaster#BrightData#PBotstealer#proxyware#certificatemisuse#TLSinfrastructureActorsCactus · Cactus Ransomware GroupIOCf48 · i16 · d36 · u8MITRE18
FILEPublicJul 28, 2026, 05:47 (UTC+9)Shared Imphash Links Pirated Keygen Trojan to Signed 2026 Installer
A single import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the thread connecting two very different-looking files: a widely pirated 2024 keygen trojan detected by 45 of 75 engines on VirusTotal, and a pair of 2026 binaries carrying a valid, unexpired code-signing certificate from a company called YAMICSOFT SOLUTIONS LIMITED.
#imphashpivoting#code-signingabuse#AgentTesla#piratedsoftwarelure#YAMICSOFTSOLUTIONSLIMITED#TA505#detectionevasion#commoditymalwareActorsTA505 · Hive0065IOCf52 · i0 · d0 · u0MITRE10RegionsAT · AU · BE · BOIndustriesTechnology
C&CMembersJul 28, 2026, 05:37 (UTC+9)Fake uTorrent Installer Uses Malformed Signature to Hide Decade-Old Adware
A Windows installer branded as uTorrent build 331 carries an Authenticode signature that fails validation outright — VirusTotal's own signing verdict states plainly that "the digital signature of the object is malformed," pointing analysts to the decade-old Microsoft security bulletin MS13-098 that documented exactly this class of forgeable signature block.
#DealPly#InstallCore#uTorrent#adware#codesigningabuse#pay-per-install#downloadredirector#AzionCDNIOCf8 · i2 · d3 · u2MITRE34RegionsBRIndustriesSupport Services
C&CMembersJul 27, 2026, 05:36 (UTC+9)UnionPay-Named TLS Certificate Found Reused Across Three Chinese ISPs
A single TLS certificate presenting the subject line `*.unionpayintl.com is now live on three IP addresses spread across three separate Chinese autonomous systems — 61.160.230.232 on AS140293 (CHINATELECOM Jiangsu province Changzhou 5G network), 58.216.102.31 on AS134769 (ChinaNet Jiangsu Changzhou Liyang IDC network), and 218.92.141.107 on AS4134 (Chinanet).
#Ludashi#unwantedx#adware#codesigningcertificateabuse#TLScertificatereuse#PUAbundling#ChineseISPs#DigiCertActorsFIN6 · Skeleton SpiderIOCf29 · i5 · d3 · u2MITRE38IndustriesEducation & Research · Wholesale