C&CMembersJun 28, 2026, 05:50 (UTC+9)Cridex C2 Pool Spans Seven Nodes Across Four Continents on One Encoded Path
At least seven command-and-control nodes spread across Indonesia, Brazil, Thailand, Mexico, and three additional unattributed locations are currently bound by a single hardcoded encoded URI path — /VJuPpCAAA/Vxi22CAAA/AHYe — embedded in a Cridex banking trojan payload that first surfaced in October 2012 and continues to generate active threat-feed hits.
#Cridex#Zbot#bankingtrojan#C2infrastructure#invoicelure#multi-noderesilience#Indonesia#MexicoIOCf3 · i4 · d0 · u12MITRE25
FILEMembersJun 28, 2026, 02:17 (UTC+9)Trojanised BitTorrent Installer Evades 74 of 75 AV Engines in 33-Country Campaign
A 4.3 MB Windows executable presenting full BitTorrent branding — product name "BT® Classic," version 51.1054.0.0, copyright "©2026 BitTorrent Limited" — is circulating as a trojanised installer that achieves a 1-in-75 detection rate while routing harvested credentials to a colocation block in Iceland whose servers answer with a *.utorrent.com TLS certificate.
#trojanisedinstaller#credentialharvesting#WebView2credentialstores#Icelandcolocationinfrastructure#CloudFrontC2#governmentandtelecomtargeting#BobSoftpacker#BitTorrentlureIOCf53 · i5 · d2 · u0MITRE70RegionsAD · AR · AT · BAIndustriesGovernment · Media · Technology
C&CMembersJun 28, 2026, 02:03 (UTC+9)One Plesk Cert Ties Four Lumma Stealer .su Domains Together
Four freshly minted .su domains — bendavo.su, conxmsw.su, narroxp.su and squeaue.su — all resolve to the same Russian-hosted IP address, share the same pair of nameservers, and present, byte for byte, an identical TLS certificate. That last detail is the tell: the certificate's subject alternative name literally hard-codes the hosting IP address into its hostname, a fingerprint that exposes what looks like four independent command-and-control domains as a single rotating front end sitting…
#LummaStealer#commandandcontrolinfrastructure#Pleskpanel#Proton66#domainrotation#VBAmacromalware#Wextractmasquerading#commodityinfostealerIOCf18 · i2 · d5 · u9RegionsCL · RO
APTMembersJun 28, 2026, 01:25 (UTC+9)Shared Imphash Ties Four 'Different' Stealers to One Builder Stub
Four Windows executables carrying four unrelated antivirus labels — AgentTesla, Bobik, "Reline," and an unnamed loader named pctool.exe — turn out to share the same import-table fingerprint, imphash f34d5f2d4577ed6d9ceec516c1f5a744, and the same PEiD packer signature. That single build lineage is the most durable and reproducible signal in an 18-file, 6-domain cluster CTX Team has been tracking: a commodity builder-and-stub layer that antivirus vendors are classifying as though it produced four…
#RedlineStealer#AgentTesla#Bobik#Socelars#Fabookie#LazarusGroup#pay-per-installdistribution#imphashclusteringActorsLazarus Group · Hastati GroupIOCf18 · i3 · d6 · u17RegionsFR
APTPublicJun 27, 2026, 21:07 (UTC+9)Donot Team Hides Cryptominer Behind Tor C2 and Anti-VM Evasion
A single 7,149-kilobyte Windows executable — packed, obfuscated, and deliberately named to impersonate a core Windows process — encapsulates one of the more analytically provocative payload configurations CTX Team has observed in a recent APTC-35 dataset. The binary, classified as trojan.dekimine and bearing the meaningful installation path %APPDATA%\pwo6\svchost.exe, does not merely steal data or open a remote shell.
#APTC-35#DonotTeam#dekimine#cryptomining#TorC2#sandboxevasion#Poland#UPXpackingActorsAPTC35 · Donot TeamIOCf58 · i1 · d0 · u0MITRE29RegionsPL
APTMembersJun 27, 2026, 16:55 (UTC+9)Seven Hostnames, One Timestamp: Mapping the yazanboss Dynamic-DNS Block
Seven near-identical hostnames — 1yazanboss.no-ip.biz through 6yazanboss.no-ip.biz, plus a bare yazanboss.no-ip.biz — were all created at the exact same second, 2001-11-22T23:09:02Z, under a single Vitalwerks Internet Solutions, LLC / No-IP.com account, with matching admin and billing contacts listed out of Reno, Nevada on every WHOIS record.
#yazanboss#DynamicDNS#No-IP.com#Sality#SaltySpider#USB-autorun#polymorphicpacker#retailsectorActorsSalty Spider · KuKuIOCf6 · i0 · d7 · u0MITRE49RegionsUSIndustriesRetail
FILEPublicJun 27, 2026, 14:07 (UTC+9)ZBot Dropper Targets Italy's Food Sector in Espionage Campaign
A 191-kilobyte Windows executable named to look like a scanned document attachment has been circulating against Italian food and beverage companies, carrying a layered evasion stack that walks past automated analysis environments before injecting a PandaBanker payload into a legitimate host process. The file — submitted to VirusTotal under the name Allegato_02,Allegato_01.Tif.exe, where allegato is Italian for "attachment" — exploits the double-extension convention to make a Win32 executable…
#BambooSpider#PandaBanker#ZBot#VBInject#foodandbeveragesector#Italy#processinjection#sandboxevasionActorsBamboo SpiderIOCf2 · i0 · d0 · u0MITRE37RegionsITIndustriesFood & Beverages
FILEMembersJun 27, 2026, 10:16 (UTC+9)One Stolen Microsoft Cert Binds Four-Malware Toolkit Targeting Farms
A financially motivated operator has assembled a four-component malware toolkit — Azorult credential stealer, ClipBanker cryptocurrency hijacker, a KillAV module, and an Andromeda dropper — and stamped every piece with the same stolen or forged Microsoft Corporation code-signing certificate, serial number 33 00 00 01 87 72 17 72 15 59 40 C7 09 00 00 00 00 01 87, signing date 2020-07-20.
#Azorult#ClipBanker#Andromeda#KillAV#code-signingcertificateabuse#agriculturesector#BrazilColombiaItaly#PS2EXEIOCf9 · i2 · d0 · u2MITRE43RegionsBR · CO · ITIndustriesAgriculture
FILEMembersJun 27, 2026, 09:45 (UTC+9)Ten-Year-Old ranapama Injector Still Harvesting US Retail Credentials in 2026
A Win32 injector compiled in June 2015 and first submitted to public malware repositories that same month is running active credential-theft operations against US retail targets in 2026 — not as a curiosity or a legacy artifact, but as a functional, evasion-engineered payload routing traffic through a 51-node relay pool spanning at least ten autonomous systems across Eastern Europe, the Caucasus, and Western Europe.
#ranapama#processhollowing#credentialharvesting#USretail#sandboxevasion#LeaseWebNetherlands#EasternEuroperelayinfrastructure#packedinjectorIOCf1 · i51 · d0 · u8MITRE30RegionsUSIndustriesRetail
C&CMembersJun 27, 2026, 09:20 (UTC+9)36 'sslsecure' Domains Mask a Templated Adware Pipeline
Thirty-six hostnames sit behind an indicator set that VirusTotal enrichment and registrar records tie to a single naming convention: sslsecure<N>.com, reproduced apex-for-apex with an identical api.v2., track.v2., and staticrr. subdomain triplet bolted onto each one. The pattern runs from sslsecure2.com through sslsecure10.com, and it isn't cosmetic — it's a templated hosting fabric built to look, at a glance, like generic SSL or security infrastructure rather than adware plumbing.
#domaiq#PUP/adware#domaininfrastructure#registrarabuse#codesigningabuse#USretailsector#ztomy.comnameservers#masqueradingIOCf2 · i1 · d36 · u0MITRE29RegionsUSIndustriesRetail
FILEMembersJun 27, 2026, 05:44 (UTC+9)One lolMiner Kit, Repackaged 20 Ways, Beats Static Detection
Twenty of the forty-three file indicators feeding this campaign are not independent malware samples — they are one dropped cryptomining toolkit, copied and renamed across batch scripts, shell scripts, a VBA-tagged loader pair, a ZIP archive and a single compiled Windows binary. Every one of them shares the identical directory scaffold resources/bin/lolminer/1.98a/ and duplicated install paths under %ProgramFiles%\CommonProgramFiles(x86)\microsoft shared\{bc4eaae6|71d5719f}\lolminer\1.98a\.
#lolMiner#cryptojacking#batchscriptmalware#dynamicDNSinfrastructure#unsignedbinaries#multi-coinmining#Dynu#ContabohostingIOCf43 · i2 · d2 · u2MITRE48RegionsAU · BE · BR · CAIndustriesConstruction · Media · Retail
C&CPublicJun 27, 2026, 05:28 (UTC+9)Amadey Credential Stealer Slips Past Sandbox Despite 60/79 AV Flags
Sixty of seventy-nine antivirus engines call it outright malicious. Feed the same file to a sandbox, and it comes back clean — "undetected," classified only as UNKNOWN_VERDICT, zero out of one dynamic runs flagging anything at all. That is the story sitting inside a single Amadey-linked credential-stealer DLL, tracked internally as cred.dll, and it is a more useful data point than most of the noisier campaign narratives this desk sees in a given week: a textbook illustration of how a passive…
#Amadey#credentialstealer#DLLmalware#sandboxevasion#C2infrastructure#Russia#YARAdetection#PleskhostingIOCf2 · i1 · d0 · u1MITRE10RegionsBG
C&CMembersJun 27, 2026, 05:07 (UTC+9)A 2012 Domain Registration Still Feeds a Fake Firefox Installer Today
Three domains bulk-registered on a single day in October 2012 are still actively serving software downloads today, and CTX Team's infrastructure mapping ties the pair of IP addresses behind their apparent callback layer to a shared TLS certificate spanning two European countries under one Brazilian CDN provider's autonomous system.
#DealPly#PUPdistribution#Baixaki#AzionTechnologies#code-signingbypass#Firefoximpersonation#CDNinfrastructure#BrazilIOCf7 · i2 · d3 · u1MITRE34RegionsBRIndustriesTechnology
FILEMembersJun 26, 2026, 22:27 (UTC+9)njRAT Campaign Hides C2 Behind Free Cloud Platforms for Three Years
An njRAT operator running a build pipeline that has remained functionally intact since at least February 2023 has systematically routed command-and-control traffic through Cloudflare Pages, Netlify, and Render — three free-tier hosting platforms whose shared wildcard TLS certificates make per-subdomain blocking operationally impractical without disrupting entire legitimate services.
#njRAT#Bladabindi#free-tierPaaSabuse#AES-encrypteddelivery#.NETReactor#UACbypass#DDNSinfrastructure#VietnamhostingIOCf7 · i1 · d5 · u4MITRE32RegionsUS
APTMembersJun 26, 2026, 20:56 (UTC+9)APT29's 2013 MiniDuke Implant Still Beaconing via Aftermarket Domain in 2026
Sixty-three of 76 antivirus engines correctly identify the 326-kilobyte Windows executable bearing SHA-256 05e4224d4dd4e5fbd381ed33edb5bf847fbc138fbe9f57cb7d1f8fc9fa9a382d as a MiniDuke Stage 3 trojan — yet one of only two sandboxes that processed it returned a 97-percent-confidence verdict of harmless. That split is not a data anomaly. It is the point.
#APT29#MiniDuke#HongKong#sandboxevasion#C2infrastructure#espionage#aftermarketdomain#dynamicanalysisevasionActorsAPT29 · MinidionisIOCf1 · i0 · d1 · u34MITRE12RegionsHK
FILEPublicJun 26, 2026, 18:17 (UTC+9)Fake Chinese PDF App Delivers ValleyRAT to Jordan's Food Sector
A 1,649-kilobyte Windows executable named kvipgui.exe — dressed as "极光PDF" (Aurora PDF), a plausible Chinese productivity application — has been circulating as a ValleyRAT shellcode runner targeting food and beverage organisations in Jordan, according to CTX Team analysis. The binary's most immediate deception is structural: it carries a DigiCert-rooted code-signing certificate issued to Shanghai entity 茉柏枘(上海)软件科技有限公司 that expired on 30 May 2024, yet the PE timestamp reads 29 April 2024 and…
#VoidArachne#ValleyRAT#foodandbeveragesector#Jordan#code-signingcertificateabuse#shellcoderunner#C2infrastructure#sandboxevasionActorsVoid Arachne · Silver FoxIOCf2 · i1 · d0 · u0MITRE26RegionsJOIndustriesFood & Beverages
C&CPublicJun 26, 2026, 17:36 (UTC+9)Upatre C2 Network Hides in Hungarian and Rural US ISP Space
A 74-kilobyte Windows executable disguised as a scanned business document sits at the centre of a command-and-control network that deliberately avoids the commercial hosting fabric most threat-intelligence feeds are tuned to watch. Both enriched relay nodes in this campaign occupy address space belonging to small, non-commercial internet service providers — one a Hungarian broadband operator in Budapest, the other a rural telephone cooperative in the American Midwest — while three additional C2…
#Upatre#C2infrastructure#spearphishingattachment#foodandbeverages#Italy#regionalISPabuse#downloadermalware#PE32stubIOCf3 · i2 · d0 · u5RegionsITIndustriesFood & Beverages
C&CMembersJun 26, 2026, 17:23 (UTC+9)1997-Timestamped Malware Resurfaces With 2025 C2 Infrastructure
A single unsigned Win32 executable, first submitted to VirusTotal in June 2015 and carrying a PE timestamp deliberately set to October 1997, is appearing alongside command-and-control infrastructure provisioned as recently as December 2025 — a temporal gap of more than a decade that sits at the heart of one of the more analytically interesting evasion puzzles CTX Team has examined this cycle. The payload targets consulting-sector organisations in the United States.
#consultingsector#PEtimestampmanipulation#sandboxevasion#C2infrastructure#indicatorremoval#packedmalware#UnitedStates#debuggerevasionIOCf3 · i2 · d0 · u5MITRE16RegionsUSIndustriesConsulting
APTMembersJun 26, 2026, 17:09 (UTC+9)Sims 4 Crack Installer Still Feeds Same CyberGate RAT
Two unsigned Windows executables masquerading as pirated copies of "The Sims 4" — both stamped with the identical PE build timestamp of 2025-03-13, both traced through directory paths reading `setup_TS4.exe and setup_TS4.tmp — sit at the center of a small but instructive campaign that pairs a piracy lure with a fully evasion-aware RAT/keylogger payload. What makes this cluster notable isn't its scale; it's the discipline.
#DustSquad#CyberGate#KeyloggerGeneric#Sims4crackinstaller#dynamicDNSC2#sandboxevasion#telecomsectortargeting#NSISdropperActorsDustSquad · APTC34IOCf10 · i0 · d1 · u1MITRE35RegionsCH · ES · KR · PLIndustriesTelecommunications
FILEMembersJun 26, 2026, 10:15 (UTC+9)A ZIP, a Batch Script, a Fake PDF Previewer: Inside a Staged Malware Chain
A cluster of 24 file indicators submitted between June 1 and June 24, 2026 traces a delivery pattern that looks less like a single tailored intrusion and more like an assembly line: an archive carrying one batch script, a MSIL loader wearing the metadata of a document-preview utility, and a separate stealer sample whose YARA hits span everything from ransomware command detection to crypto-wallet browser extension harvesting.
#AgentTesla#XWorm#commoditymalware#MSILloader#ZIParchivedelivery#browsercredentialtheft#sandboxevasion#builder-kitmalwareIOCf24 · i1 · d0 · u1MITRE38RegionsBR · EG · ES · GBIndustriesAutomotive · Consulting · Education & Research
C&CPublicJun 26, 2026, 09:35 (UTC+9)Cracked-Software Lure Bundles Three RAT Families From One Build Pipeline
A trojanised archive circulating under the name "Onimai 1.7.1" — presented to prospective victims as a cracked copy of a software application — packages three distinct remote-access trojan families into a single deployment bundle, all compiled from what the evidence indicates is a unified .NET build pipeline and routed through the playit.gg public tunnelling service to a self-signed command-and-control node registered in the Seychelles but geolocated in Germany.
#MrThunker#QuasarRAT#XWorm#VenomRAT#cracked-softwarelure#playit.ggtunnelling#FodyCosturapacking#commodityRATIOCf9 · i1 · d0 · u1
APTPublicJun 26, 2026, 09:21 (UTC+9)Barium Hides Cobalt Strike Behind Spoofed BugSplat DLL and Expired Demo Certificate
A 938-kilobyte ZIP archive circulating since late December 2024 carries one of the more deliberately layered evasion chains CTX Team has documented in recent months: a Cobalt Strike loader campaign attributed to Barium that deploys a spoofed BugSplat crash-reporter DLL, an opaque encoded second stage, active sandbox-detection logic, and a C2 node presenting an expired OpenSSL demo certificate with the common name set to 8.8.8.8 — Google's public DNS resolver.
#Barium#CobaltStrike#DLLsideloading#TerndoorLoader#foodandbeveragesector#Jordan#OpenSSLdemocertificate#encodedpayloadActorsBarium · Wicked SpiderIOCf5 · i1 · d0 · u1RegionsJOIndustriesFood & Beverages
FILEMembersJun 26, 2026, 02:43 (UTC+9)EV Certificate Held 13 Months Before Signing Four Malicious Payloads
Four Windows executables and an MSI installer, all bearing a valid Sectigo Extended Validation code-signing certificate issued to a company called "ORYON TECH LIMITED," began circulating through cracked-software distribution channels in April 2026 — but the certificate that makes them look legitimate to Windows SmartScreen and most endpoint defences was acquired more than a year before the first payload ever appeared.
#ORYONTECHLIMITED#Microleaves#Legionadware#LummaStealer#EVcertificateabuse#pay-per-install#sandboxevasion#RomaniaIOCf20 · i1 · d5 · u13MITRE29RegionsSRIndustriesRetail · Telecommunications
APTMembersJun 26, 2026, 01:23 (UTC+9)Decade-Old Keygen Trojan Anchors Multi-Stage Pakistan Espionage Chain
Since CTX Team's earlier coverage of this operation, six new files have surfaced that materially deepen the picture of how the Godzilla Loader and PonyStealer campaign targeting Pakistan actually functions — not just what it delivers, but how it gets there. The new components introduce a second build cluster absent from prior analysis: a batch-script orchestrator, an invalid-signed SOCKS5 proxy tool, a PEiD-packed .NET spreader, and a delivery archive built around a keygen lure that has been…
#GodzillaLoader#PonyStealer#Pakistanespionage#keygentrojan#SOCKS5proxy#credentialtheft#C2infrastructure#spreadermalwareIOCf17 · i0 · d5 · u9MITRE34RegionsPK
FILEMembersJun 25, 2026, 22:43 (UTC+9)Single Obfuscation Builder Links BAT Stager and MSIL Dropper in 19-Country Campaign
An 8-kilobyte DOS batch file and an 85-kilobyte .NET executable — separated by file type, detection rate, and apparent purpose — turn out to share a single obfuscation fingerprint that binds them into a deliberately engineered attack chain. The YARA rule SUSP_PS1_JAB_Pattern_Jun22_1, authored by Florian Roth of Nextron Systems and drawn from the Neo23x0 signature-base, co-fires on both components: the batch stager (SHA-256 02af6b5d…) and the MSIL dropper (SHA-256 d35dbfec…).
#MSILdropper#BATstager#PowerShelldownloader#Bitviseimpersonation#content-typespoofing#sandboxevasion#technologysector#multi-countrycampaignIOCf9 · i0 · d1 · u2MITRE30RegionsAT · BD · CA · CHIndustriesAgriculture · Education & Research · Media
APTMembersJun 25, 2026, 20:56 (UTC+9)EV Certificate Minted for One Campaign Powers Three-Layer Evasion Chain
Thirty-nine days. That is the total operational window separating the moment a Sectigo Extended Validation certificate was issued to an entity called QUANTIS LOGIK LTD and the moment the two PE32 installers it signed first appeared on VirusTotal. The certificate — serial number 00 86 51 B4 B7 A5 AF 08 DF 82 E5 FE 4E 5B 99 A8 18, thumbprint 1080D4CCFE6E5EE372CB3DB8686C37923A932AF5, issued 2026-04-22, used to sign both payloads on 2026-05-19, with the files submitted on 2026-06-01 — was not a…
#LummaStealer#OfferCore#EVcertificateabuse#CloudFrontdomain-fronting#sandboxevasion#LazarusGroup#telecomsector#code-signingabuseActorsLazarus Group · Hastati GroupIOCf2 · i0 · d1 · u0MITRE21RegionsCO · DE · EG · FRIndustriesAgriculture · Support Services · Telecommunications
FILEMembersJun 25, 2026, 18:28 (UTC+9)Salty Spider Hides Expiro in Adobe's Own Sandbox Temp Path
A 60-kilobyte GZIP archive, first submitted to VirusTotal on 22 March 2025, sits at the centre of an evasion architecture that has so far produced zero detections across 78 scanning engines. The file's distinguishing feature is not its contents — those remain opaque without a sandbox verdict — but where it lives: every observed submission path resolves to C:\Users\user\AppData\Local\Temp\acrocef_low\, the low-integrity process temp directory belonging to Adobe Acrobat's Chromium Embedded…
#SaltySpider#Expiro#AdobeAcrobatCEFsandbox#CDNcertificatemasquerade#AkamaiTLSspoofing#DigiRomaniaASN8708#enterpriseendpointevasion#fileinfectorActorsSalty Spider · KuKuIOCf55 · i1 · d0 · u0MITRE29
C&CPublicJun 25, 2026, 17:58 (UTC+9)Finance-Lure VBScript Spoofs CSV Type to Evade Static Scanners
Three new file variants have surfaced in an ongoing Formbook delivery campaign that CTX Team has been tracking since its prior coverage (earlier coverage), and the most significant change is not a new payload family or a fresh infrastructure node — it is a quiet manipulation of file-type metadata. The outer ZIP container drops a VBScript downloader whose file magic is reported as "CSV text" despite carrying a .vbs extension and an uncompressed size of nearly two megabytes, a type-confusion…
#Formbook#VBScript#file-typespoofing#financelure#commodityinfostealer#phishingattachment#C2infrastructure#accounts-payabletargetingIOCf3 · i0 · d1 · u2RegionsBD · BE · CA · CHIndustriesAerospace · Construction · Consulting
C&CMembersJun 25, 2026, 17:35 (UTC+9)One Ukrainian IP, Four One-Letter Payloads, Zero Sandbox Alarms
A 182-kilobyte Windows executable that 63 of 75 static antivirus engines flag as malicious walks through dynamic analysis without triggering a single sandbox alarm. That contradiction — near-universal static detection paired with a 99-confidence CLEAN verdict from Zenbox — sits at the centre of an active Phorpiex-and-GandCrab distribution operation whose entire observable infrastructure collapses to a single Ukrainian IP address, 92.63.197.106, operating under ASN 211736 (FOP Dmytro Nedilskyi).
#Phorpiex#GandCrab#sandboxevasion#single-IPinfrastructure#ransomwaredistribution#Ukraine#wormpropagation#dropperIOCf4 · i1 · d0 · u6MITRE38RegionsCN
FILEMembersJun 25, 2026, 14:18 (UTC+9)Gorgon Group Wraps Commodity Stealers in Four-Layer Evasion Stack
A GZIP archive bearing the filename "RFQ Number QUO19009852.exe" is the outermost layer of a credential-theft operation that CTX Team has been tracking against Windows endpoints. The file is unremarkable at first glance — a compressed archive mimicking a supplier quotation request, the kind of attachment that moves through purchasing inboxes without triggering much suspicion.
#GorgonGroup#ponystealer#predator_pain#PEiDpacking#spear-phishing#credentialtheft#anti-forensictimestamp#procurementlureActorsGorgon Group · SubaatIOCf7 · i0 · d0 · u0MITRE41
FILEMembersJun 25, 2026, 10:07 (UTC+9)LummaStealer Campaign Hides Nine C2 Domains Behind One Server
Nine command-and-control domains provisioned in a single week in December 2025 form the backbone of an active LummaStealer campaign targeting India — and the infrastructure's construction reveals an operator who planned for partial takedown from the outset. Eight of those domains share a single self-signed TLS certificate serial and, in seven cases, a single resolving IP address, meaning the elaborate domain pool amounts to DNS-level wallpaper over one physical server.
#LummaStealer#AutoItdropper#C2infrastructure#India#credentialtheft#self-signedTLS#malware-as-a-service#infrastructurecompartmentalisationIOCf10 · i0 · d9 · u17MITRE31RegionsIN
C&CPublicJun 25, 2026, 05:44 (UTC+9)Purchase-Order VBS Downloader Now Delivers XWorm, Not Formbook
A VBS script disguised with a CSV file signature — the same purchase-order-themed downloader CTX Team tracked in earlier coverage of this delivery chain — now sandboxes to a different terminal payload entirely. Where the prior reporting on this lineage centered on a Formbook loader, the newly submitted sample returns a 3/3 malicious consensus across CAPE Sandbox, Zenbox, and Yomi Hunter, with the sandbox layer explicitly naming the deployed family as XWorm, a commodity remote-access trojan.
#XWorm#Formbook#VBScriptdownloader#purchaseorderlure#basefile.click#KeyAuth#remoteaccesstrojan#phishingIOCf3 · i0 · d1 · u2RegionsAT · AU · BD · CAIndustriesCommercial Services · Education & Research · Government
C&CPublicJun 25, 2026, 01:55 (UTC+9)DCRat Campaign Hides C2 Traffic Behind Fake Google Analytics TLS Cert
A single attacker-controlled domain is currently staging a DCRat remote-access trojan behind a TLS certificate whose subject common name reads *.google-analytics.com — a deliberate impersonation of Google's telemetry infrastructure designed to make outbound C2 traffic appear, to any network sensor performing only certificate-level inspection, as routine analytics beaconing.
#ManicMenagerie#DCRat#TLScertificateimpersonation#Germany#bulletproofhosting#authenticodeevasion#C2infrastructure#packedmalwareActorsManic MenagerieIOCf1 · i1 · d1 · u2RegionsDE
APTPublicJun 24, 2026, 21:30 (UTC+9)TA505 Rockloader C2 Hits SE Asia Finance With Zero Detections
Three command-and-control domains registered within five weeks of each other, scoring zero detections across 91 antivirus engines, with WHOIS identity fields uniformly padded with the same 16-character hex string — this is the operational signature CTX Team has mapped to a TA505-attributed rockloader campaign currently targeting financial-services organisations in Cambodia and Singapore.
#TA505#rockloader#command-and-controlinfrastructure#financialservices#Cambodia#Singapore#DGA#WHOISobfuscationActorsTA505 · Hive0065IOCf9 · i0 · d3 · u0MITRE32RegionsKH · SGIndustriesFinancial Services
C&CMembersJun 24, 2026, 13:54 (UTC+9)Upatre Downloader Returns With Anti-Analysis Stack Shielding FTP C2
Three Windows PE droppers surfaced in CTX Team's feed on June 24, 2026, carrying a threat label that many defenders might dismiss on sight: Upatre, a downloader family old enough to have been circulating when the Czech ISP subnet it now phones home to was first registered. That familiarity is precisely the risk. The current cluster — tracked as CTX4uky7ju34a — pairs the family's well-worn FTP-based payload retrieval with a layered anti-analysis stack that sequences time-based sandbox checks…
#Upatre#FTPC2#anti-analysisevasion#CzechRepublicinfrastructure#downloader#sandboxevasion#securitytooldisablement#post-executioncleanupIOCf3 · i1 · d0 · u4MITRE13
C&CMembersJun 24, 2026, 10:03 (UTC+9)One PHP Path, Four Servers, Ten Years: Inside an APT's C2 Framework
Four IP addresses. One identical endpoint. The string /upload/_dispatch.php — replicated without variation across a quartet of Russian-hosted servers — is the clearest fingerprint CTX Team has extracted from a campaign carrying espionage motivation and APT classification in the threat record. The infrastructure has been operationally maintained from at least mid-2016 through confirmed certificate activity in June 2026, a decade-long window that makes the uniformity of that PHP path all the more…
#APT#C2infrastructure#PHPframework#Turkeyespionage#masquerading#dynamicimportresolution#self-signedcertificate#OPSECfailureIOCf14 · i2 · d11 · u7RegionsTR
APTMembersJun 24, 2026, 01:23 (UTC+9)Fake YCleanner App Delivers LummaStealer After Four-Month Build Campaign
A Windows executable branded as a system-cleaning utility — product name "YCleanner," internal name YC.exe, version 1.3.2.5 — has been circulating as the delivery vehicle for a dual-purpose attack chain combining LummaStealer credential theft with XMRig cryptomining, targeting Romania. The campaign's most operationally distinctive feature is not the payload itself but the architecture surrounding it: an encrypted outer container that achieves a clean sweep of 0/77 antivirus detections at the…
#BlueBottle#LummaStealer#XMRig#Romania#credentialtheft#cryptomining#fakesoftwarelure#Opera1erActorsBlueBottle · Opera1erIOCf16 · i0 · d1 · u1RegionsRO
FILEMembersJun 23, 2026, 22:05 (UTC+9)WZTeam KMS Trojan Stacks Five Evasion Layers Behind 23-Year Cert
##A 23-Year Certificate and Five Stacked Evasion Layers: Inside the WZTeam KMS Trojan Chain Three UPX-packed Windows executables presenting as KMSAuto++ activation tools have been circulating with a self-issued code-signing certificate that carries a validity window stretching to the year 2039 — a deliberate, long-lived signing identity engineered to pass casual inspection at the moment a user decides whether to run a crack.
#WZTeam#KMSAuto#Koadic#PowerShelldownloader#code-signingabuse#Mexico#Philippines#defenseevasionActorsAPT27 · TEMP.HippoIOCf9 · i1 · d0 · u2RegionsMX · PH
C&CPublicJun 23, 2026, 17:22 (UTC+9)SWIFT-Lure ZIP Drops Formbook via 2 MB Sleep-Padded VBScript
A thirteen-kilobyte ZIP file named "Swift-015062026.zip" is circulating across at least 35 countries, carrying a single child file that expands to nearly two megabytes of VBScript — a deliberate size anomaly engineered to exhaust static scanners and outlast the time-boxed execution windows that automated sandboxes rely on. When a recipient opens the archive and runs the enclosed script, they are handing a Formbook infostealer a foothold on their machine, with credentials, keystrokes,…
#Formbook#VBScriptdropper#SWIFT-themedphishing#sandboxevasion#basefile.click#financialservices#infostealer#spear-phishingattachmentIOCf3 · i0 · d1 · u2RegionsAT · BA · BD · BEIndustriesAerospace · Construction · Consulting
C&CMembersJun 23, 2026, 09:22 (UTC+9)WoodyRAT C2 Expands With Ukrainian Node, Traefik Relay, and .biz Domain Pair
Since CTX Team's earlier coverage of this WoodyRAT-attributed infostealer campaign, the operator has not stood still. Fifteen new file indicators and five new domains have entered the observable set, but the most analytically significant additions are structural rather than volumetric: a Ukrainian-hosted C2 node (195.211.191.95, AS208949, Hbing Limited) that bridges into the existing German hosting cluster via a shared operator-generated wildcard certificate, two freshly registered .biz domains…
#WoodyRAT#infostealer#C2infrastructure#cryptocurrencywallettheft#Traefikreverseproxy#bulletproofhosting#Ukraine#TelegramexfiltrationIOCf42 · i4 · d5 · u7MITRE62
FILEMembersJun 23, 2026, 06:07 (UTC+9)Fake uTorrent Installers Pair Valid Code Signing With CDN Impersonation
A cluster of Windows installers dressed up as the BitTorrent and uTorrent clients is circulating alongside a supporting network layer that borrows something rarely seen in commodity adware distribution: wildcard TLS certificates minted for someone else's brand. Three unrelated hosting providers — Digi Romania S.A. (AS8708, Romania), Advania Island ehf (AS50613, Iceland), and a Singapore-registered network called ACE (AS139341) — each present certificates whose subject lines point to major CDN…
#BitTorrent#uTorrent#code-signingcertificate#CDNimpersonation#wildcardTLScertificate#CloudFront#adware#bundlewareinstallerIOCf28 · i4 · d2 · u0MITRE46RegionsBR · CA · CG · CHIndustriesEducation & Research · Technology · Telecommunications
APTMembersJun 23, 2026, 00:58 (UTC+9)Trojanised Adobe Firefly Installer Runs Triple-Monetisation Kill Chain on Construction Firms
Pirated creative software has long been a reliable vector for commodity malware, but a campaign CTX Team has been tracking shows how far that distribution model has matured. Two oversized Windows executables — both named FireflyAI.exe, one weighing 45 MB and the other 53 MB — are circulating as trojanised installers for Adobe's Firefly AI tool, with one sample's embedded path string explicitly referencing "Firefly AI 25.0.0.2265 beta for Adobe Photoshop 24.7 (x64)." The lure has been active…
#PureLogs#WinRing0BYOVD#Nanopool#trojanisedinstaller#constructionsector#credentialtheft#crypto-mining#C2infrastructureActorsAPT28 · StrontiumIOCf21 · i4 · d5 · u4RegionsBR · DE · LUIndustriesConstruction
FILEMembersJun 22, 2026, 18:33 (UTC+9)Revoked 2005 Certificate Still Delivering LSA Credential Stealer in 2026
A Windows executable bearing a webHancer Corporation code-signing certificate — issued by ThawteCode Signing CA, valid only from August 2004 to September 2005, explicitly distrusted, time-invalid, and with revocation status listed as offline — was submitted to threat intelligence platforms as recently as March 6, 2026. That single observation frames everything that follows: a multi-component bundle combining two distinct mid-2000s adware product lines, a versioned auto-update delivery mechanism…
#LSAcredentialdumper#adware-trojanhybrid#revokedcode-signingcertificate#NewDotNet#webHancer#CEDP.Stealer#telecommunicationssector#sandboxevasionIOCf16 · i2 · d2 · u4MITRE43RegionsGB · MXIndustriesTelecommunications
FILEMembersJun 22, 2026, 18:17 (UTC+9)Meteorite Downloader Delivers Azorult and OskiStealer to Media Targets
A Varist-packed dropper self-identifying as "Meteorite Downloader v3.01" has been observed targeting media organisations in Canada, France, and the United States, delivering Azorult and OskiStealer credential-theft payloads through a layered evasion stack that combines timing-based sandbox defeat, three concurrent process-injection sub-techniques, and active suppression of security tooling.
#MeteoriteDownloader#Azorult#OskiStealer#Varistpacker#mediasector#processinjection#credentialtheft#multi-clusterinfrastructureIOCf3 · i0 · d11 · u3MITRE21RegionsCA · FR · USIndustriesMedia
C&CMembersJun 22, 2026, 17:26 (UTC+9)Nine-File Toolchain With Zero PE Imports Targets Six Countries via Dedicated AS
Nine Windows executables, zero PE imports between them, and a dedicated binary whose sole purpose is to kill endpoint defenses before the rest of the payload stack arrives — this is the operational profile of a campaign CTX Team has been tracking since late May 2026, one that pairs an unusually complete evasion architecture with a purpose-built autonomous system that its operator has been quietly expanding for the better part of a year.
#WoodyRAT#BazarLoader#Amadey#ClipBanker#EDRbypass#AS214351#credentialharvesting#reflectiveDLLinjectionIOCf26 · i3 · d5 · u6MITRE66RegionsDZ · ES · ID · IT
FILEMembersJun 21, 2026, 21:17 (UTC+9)Godzilla Loader Campaign Byte-Mutates Five Variants, Exfiltrates India Victim's Documents
Five nearly identical 9-kilobyte Windows executables are circulating as the primary delivery mechanism for a Godzilla Loader campaign whose most operationally revealing detail is not the malware itself — it is the five zero-detection text files sitting in the same dataset, each one a harvested document from a victim's own machine, packaged with a unique victim token and dual collection timestamps from July and August 2024.
#GodzillaLoader#FileGrabber#India#dataexfiltration#bytemutation#C2infrastructure#PE32loader#stealerIOCf12 · i0 · d5 · u6MITRE30RegionsIN
FILEMembersJun 21, 2026, 17:14 (UTC+9)EV-Signed Video Downloader Hides MSSQL Backdoor, Hits Zero AV Detections
Five Windows executables distributed under two consumer software brands — PPTube and iTubeGo YouTube Downloader Pro — arrived on VirusTotal between June 3 and June 6, 2026, each bearing a validly verified Sectigo Extended Validation code-signing certificate issued to an entity called "ByteHub Technology Inc." Every antivirus engine on the platform returned a clean verdict.
#Skip-2.0#MSSQLbackdoor#EVcode-signingabuse#PyArmor#telecommunicationssector#GermanySwedenThailand#ByteHubTechnologyInc#piracy-channeldeliveryIOCf28 · i1 · d2 · u1MITRE8RegionsDE · SE · THIndustriesTelecommunications
C&CMembersJun 21, 2026, 16:41 (UTC+9)Phorpiex Botnet Adds Kernel Driver and Go Wallet Stealer in 2026 Upgrade
A Phorpiex botnet campaign active since early June 2026 has added two capabilities that sit well outside the family's historical playbook: a Bring-Your-Own-Vulnerable-Driver kernel component and a Go-runtime infostealer purpose-built to drain cryptocurrency wallet browser extensions. The combination — mass SMTP propagation, XOR-obfuscated PE droppers, XMRig cryptomining, kernel-driver abuse, and browser-extension credential harvesting, all consolidated on four command-and-control IPs inside a…
#Phorpiex#XMRig#BYOVD#WinRing0#Goinfostealer#cryptocurrencywalletharvesting#AS202412#SpainIOCf15 · i6 · d9 · u5MITRE36RegionsES · UZ
APTMembersJun 21, 2026, 16:13 (UTC+9)Emotet Hijacks Aged German Sites to Evade Detection in PNG Campaign
Four German-hosted websites — three of them registered between 2000 and 2009, all of them delegating DNS through the same Cronon/Strato nameserver infrastructure — are serving as the distribution backbone for an active Emotet campaign targeting the hospitality sector in Papua New Guinea. The cluster, observed by CTX Team between 14 and 21 June 2026, is analytically notable not for the malware it delivers but for the hosting architecture it exploits: rather than spinning up fresh…
#Emotet#TA542#CrononGmbH#rzone.de#hospitalitysector#PapuaNewGuinea#compromisedlegitimatedomains#PowerShelldownloaderActorsEmotet Group · TA542IOCf4 · i1 · d4 · u8RegionsPGIndustriesHospitality & Leisure
C&CMembersJun 21, 2026, 08:25 (UTC+9)37-Node Tox C2 Network Powers Resilient Browser Credential Stealer
A packed Windows credential stealer is communicating with its operators through five numbered Tox-protocol subdomains distributed across two operator-controlled domains — tox1.mf-net.eu through tox4.mf-net.eu and tox.libre.tw — backed by a relay network of 37 IP addresses spanning four distinct ASN cohorts that include FranTech Solutions (AS53667), iFog GmbH (AS34927), Hetzner Online GmbH (AS24940), and M247 Europe SRL (AS9009).
#BrowserStealerGeneric#Toxprotocol#credentialtheft#bulletproofhosting#DNS-over-HTTPSevasion#Let'sEncryptcertificateabuse#FranTechSolutions#WindowsmalwareIOCf1 · i37 · d3 · u5MITRE10