CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • C&CMembersJun 21, 2026, 04:14 (UTC+9)

    17-Year-Old Kernel Driver Powers 2026 Monero Mining Campaign

    A financially motivated campaign active during the week of June 19–20, 2026 is deploying XMRig 6.26.0 Monero miners behind a three-layer evasion stack that most commodity cryptomining operations never bother to assemble: a LOLDrivers-listed vulnerable kernel driver to undermine endpoint defences, a self-signed loader dressed up with a same-day certificate to slip past casual signature checks, and a game-themed NSIS dropper to carry the whole package past users who think they are installing a…

    #XMRig#WinRing0x64.sys#BYOVD#Monerocryptomining#LOLDrivers#NSISdropper#maliciouskerneldriver#game-themedlure
    IOCf53 · i1 · d3 · u0MITRE36
  • APTMembersJun 21, 2026, 04:00 (UTC+9)

    Kimsuky Hides Trojan in Npcap Installer With Valid Nmap Certificate

    A Nullsoft NSIS self-extracting installer bearing the filename npcap-1.88-oem-usnavy-testcopy-poexcu.exe — signed with a fully valid Nmap Software LLC code-signing certificate and scoring zero detections across 76 antivirus engines — represents one of the more deliberate evasion constructions CTX Team has documented in recent months.

    #Kimsuky#GuLoader#Npcap#code-signingabuse#driver-storemasquerading#defencesector#sandboxevasion#Authenticodeoverlay
    ActorsKimsuky · Velvet ChollimaIOCf33 · i0 · d0 · u0MITRE44
  • FILEMembersJun 20, 2026, 16:47 (UTC+9)

    APT28 Cracked-Software Lure Rode 16-Month-Old C2 Infrastructure

    A single Windows executable masquerading as five popular pirated applications reached 37 independent submission sources within twelve days of its first appearance — not because the operator rushed the deployment, but because the infrastructure waiting to receive it had been quietly assembled more than a year in advance. The C2 certificate was minted in January 2025. The domains were batch-registered in April 2026. The payload surfaced in June 2026.

    #APT28#Trojan.Remus/Wingo#crackedsoftwarelure#stealertrojan#C2infrastructure#sandboxevasion#credentialharvesting#Ukrainehosting
    ActorsAPT28 · StrontiumIOCf1 · i1 · d2 · u2MITRE11RegionsBD · BR · CA · CLIndustriesFood & Beverages
  • FILEMembersJun 20, 2026, 16:33 (UTC+9)

    LHA Lure Drops PureLog Stealer and XWorm With 0/76 Persistence Layer

    A 935-kilobyte ZIP archive named docPO-Q-2606010-ASN _ ZBSPR26-007.PDF(849KB).LHA is circulating as a spearphishing attachment across engineering firms, retail organisations, and telecommunications providers in Bosnia-Herzegovina, Colombia, the Czech Republic, Malaysia, and the United States. The filename is a layered deception: the .LHA extension appended after a fake PDF size annotation is engineered to make the archive read as a harmless purchase-order document to a distracted procurement or…

    #PureLogStealer#XWorm#spearphishingattachment#double-extensionlure#.NETReactor#DDNScommand-and-control#engineeringandtelecomsectors#SetupComplete.cmdpersistence
    IOCf23 · i3 · d1 · u2MITRE60RegionsBA · CO · CZ · MYIndustriesEngineering · Retail · Telecommunications
  • APTMembersJun 20, 2026, 16:10 (UTC+9)

    APT28 Hides Trojan in Pirated Software, Spreads via USB Across 22 Countries

    A 2,967-kilobyte Windows executable dressed up as "FL Studio 2025 Full Version.exe" is circulating across manufacturing and telecom networks in 22 countries, carrying a layered evasion stack that defeated one of three automated sandboxes outright — and the certificate stapled to it was issued the same day the file first appeared on VirusTotal, minted by a service that signs anything you give it.

    #APT28#trojan#USBspreader#piratedsoftwarelure#manufacturing#telecommunications#sandboxevasion#WMIexecution
    ActorsAPT28 · StrontiumIOCf1 · i1 · d3 · u3MITRE11RegionsAO · AR · AU · BOIndustriesManufacturing · Telecommunications
  • APTMembersJun 20, 2026, 15:58 (UTC+9)

    Snowglobe Adds Chrome-Extension Droppers, Leaves cheater.to Untouched

    Six new file indicators have joined the record CTX Team has been building around a Cloudflare-fronted domain called cheater.to — and none of them are new domains or IPs. That distribution alone is the story. The most consequential pair in the batch are two files that VirusTotal types as "Google Chrome Extension" containers, complete with the magic string "Google Chrome extension, version 3, XZ compressed, CRC64" — yet whose internal file paths resolve to ordinary Windows executables:…

    #Snowglobe#Babar#Vidarstealer#Salatstealer#masqueradingT1036#telecomespionage#cheater.to#Cloudflareinfrastructure
    ActorsSnowglobe · Animal FarmIOCf9 · i0 · d1 · u0MITRE43RegionsCZ · LT · SA · TRIndustriesTelecommunications
  • C&CMembersJun 20, 2026, 08:28 (UTC+9)

    Nine No-IP Subdomains, One Account: A .NET Trojan C2 Still Active in 2026

    A single No-IP dynamic DNS account holds nine sequentially enumerated subdomains — incorrect.no-ip.biz through 8incorrect.no-ip.biz — each configured with 60-second TTL A records pointing to European residential IP addresses, each sharing the same nameserver cluster (NF1 through NF5.NO-IP.COM), and each ready to absorb C2 traffic the moment any sibling is blocked or sinkholed.

    #trojan.barys#MSILtrojan#No-IPDDNS#C2infrastructure#dynamicDNSabuse#imphashclustering#EuropeanresidentialIPs#defenseevasion
    IOCf3 · i2 · d9 · u0MITRE37RegionsFR
  • C&CMembersJun 20, 2026, 04:26 (UTC+9)

    Cridex C2 Roster Ties Eight IPs to One Hardcoded URI Path

    Eight IP addresses. Five autonomous systems. Four countries. One identical URI path burned into every beacon call. That is the architecture CTX Team documented when it mapped the command-and-control roster attached to a Cridex/Dreidel trojan sample that first appeared on VirusTotal in January 2013 but was re-observed as recently as June 2026.

    #Cridex#Dreidel#C2infrastructure#hardcodedURI#compromisedserver#TLScertificateabuse#Canadahosting#Portugal
    IOCf2 · i4 · d0 · u16MITRE20
  • FILEMembersJun 19, 2026, 09:13 (UTC+9)

    Stealc v2 Adds Chrome Encryption Bypass in Two-Stage Stealer Pivot

    Twelve new files and a single Spamhaus DROP-listed IP are the visible footprint of a credential-theft operation that has materially retooled since its earlier iteration. Where prior coverage documented a SmokeLoader-based lure with multiple C2 nodes, the campaign now deploys a sequenced SVCStealer loader and Stealc v2 payload — two unsigned 64-bit Windows executables that independently check in to the same raw IPv4 address, 62.60.226.159, hosted under AS214351 (Femo IT Solutions Limited,…

    #Stealcv2#SVCStealer#infostealer#Chromeapp-boundencryptionbypass#Exoduswallet#Romania#bullet-proofhosting#two-stageloader
    ActorsAPT28 · StrontiumIOCf31 · i1 · d0 · u1MITRE42RegionsAU
  • FILEMembersJun 19, 2026, 08:48 (UTC+9)

    Gozi Banking Trojan Routes C2 Through Trio of Tor Onion Addresses

    Three algorithmically generated Tor v3 hidden-service addresses — each a 56-character base32 string indistinguishable from random noise — are currently routing bot check-ins for an active Gozi banking-trojan campaign tracked by CTX Team as CTXv7povuldk2. The addresses were not registered through any conventional registrar, carry no TLS certificates that could be fingerprinted, and leave no DNS footprint that a sinkhole could intercept.

    #Gozi#ISFB#Torhiddenservices#DGA#bankingtrojan#C2infrastructure#compile-after-delivery#datadestruction
    IOCf24 · i0 · d3 · u1MITRE38
  • FILEMembersJun 19, 2026, 05:02 (UTC+9)

    Signed Adware Dropper Hits 39 Countries With 2/76 AV Detections

    A trojanised BitComet installer bearing a commercially obtained Sectigo code-signing certificate is circulating across 39 countries, achieving a detection rate of just 2 out of 76 engines on its dropper component — not through novel exploitation or zero-day tradecraft, but through the deliberate layering of a valid certificate chain, sandbox-evasion instrumentation, and AWS CloudFront CDN abuse into what is, on the surface, a routine adware distribution campaign.

    #DealPly#Offercore#code-signingabuse#sandboxevasion#adware#Chromeextensionpersistence#CDNabuse#educationsector
    IOCf59 · i4 · d1 · u0MITRE48RegionsAL · BG · BR · BSIndustriesEducation & Research · Financial Services · Technology
  • C&CPublicJun 19, 2026, 04:26 (UTC+9)

    XWorm RAT Hides Behind Purchase-Order ZIP and Pre-Armed Wildcard Infrastructure

    ##Purchase-Order ZIP Conceals a Three-Stage XWorm Delivery Chain Built on Pre-Armed Wildcard Infrastructure A compact, eleven-kilobyte ZIP archive named PO-000172483.zip is the opening move in a campaign that unfolds across five deliberate stages — evasion-hardened VBS execution, a stealthy compile-after-delivery intermediate, and XWorm RAT C2 over a Turkish-geolocated IP whose hosting fabric was provisioned weeks before the first malicious file appeared on the internet.

    #XWorm#VBSdownloader#compile-after-delivery#purchase-orderlure#wildcardTLSinfrastructure#manufacturing#WhiteLabelServices#multi-stagedeliverychain
    IOCf9 · i1 · d2 · u3RegionsAT · BD · BR · CHIndustriesAerospace · Agriculture · Automotive
  • APTMembersJun 19, 2026, 03:56 (UTC+9)

    Spring Dragon Hides GCleaner in VR Installer With 4-Year-Old Certificate

    A Windows executable posing as an HTC VIVE Software installer has surfaced carrying a DigiCert code-signing certificate that expired in April 2021 — more than four years before the file appeared on any scanner — while beaconing to a trio of command-and-control domains registered, TLS-provisioned, and Cloudflare-proxied within a single 72-hour window.

    #SpringDragon#GCleaner#wmi_ghost#code-signingcertificateabuse#sandboxevasion#CloudflareC2proxying#HTCVIVElure#pay-per-installloader
    ActorsSpring Dragon · Lotus BlossomIOCf1 · i0 · d3 · u6MITRE12
  • FILEPublicJun 19, 2026, 00:42 (UTC+9)

    YoroTrooper's AveMaria RAT Dropper Stacks Five Evasion Layers Before C2 Contact

    Since CTX Team's earlier coverage of a WarzoneRAT cluster targeting Turkish organisations, two new file indicators have surfaced alongside the same Microsoft-themed infrastructure backbone — and the tradecraft picture they reveal is considerably more elaborate than a routine IOC refresh. The primary dropper, a 668-kilobyte Win32 PE32 executable catalogued under SHA-256 69415b18aeb7e75f4843313ed5c65e09b1a2a41d73af0ce7fed40e0f2cc2b0a0, stacks five discrete anti-analysis mechanisms before it ever…

    #YoroTrooper#AveMariaRAT#WarzoneRAT#UACbypass#processinjection#sandboxevasion#CentralAsia#typosquatinfrastructure
    ActorsYoroTrooperIOCf2 · i0 · d2 · u0MITRE21
  • FILEPublicJun 19, 2026, 00:24 (UTC+9)

    10KB SystemBC Dropper Evades Both Sandboxes in Saudi Telecom Attack

    ##A 10-Kilobyte Ghost: How a Zero-Import SystemBC Dropper Defeated Every Sandbox Targeting Saudi Telecom A single 10-kilobyte unsigned Windows executable — compact enough to fit inside a typical email attachment header — has been identified in a campaign against telecommunications infrastructure in Saudi Arabia, carrying a technical profile that exposes a deliberate gap in how most enterprise detection pipelines are built.

    #DragonForce#SystemBC#Coroxy#sandboxevasion#telecommunications#SaudiArabia#bullet-proofhosting#proxy-RAT
    ActorsDragonForce · DragonForce MalaysiaIOCf1 · i1 · d0 · u0MITRE8RegionsSAIndustriesTelecommunications
  • APTPublicJun 18, 2026, 23:57 (UTC+9)

    Upatre Dropper Fires CryptoLocker Rules as Decade-Dormant Domain Wakes

    A 27-kilobyte Windows executable named case_10022013.exe sits at the centre of a delivery chain that has been quietly circulating since at least October 2013 — and the most analytically striking detail is not its age but its identity crisis. The binary is classified by 66 of 77 antivirus engines as Upatre, the compact downloader long associated with the Gold Evergreen / Business Club criminal ecosystem.

    #GoldEvergreen#BusinessClub#Upatre#CryptoLocker#ZBot#legal-lurephishing#long-dormantC2infrastructure#dual-familymalware
    ActorsGold Evergreen · Business ClubIOCf3 · i0 · d1 · u1MITRE9
  • FILEPublicJun 18, 2026, 20:29 (UTC+9)

    AgentTesla Stealer Activates Three-Year-Old Tanzanian Domain in Single Day

    On the morning of 2 June 2026, two events occurred in close enough succession to rule out coincidence. At 12:23:47 UTC, a 90-day wildcard TLS certificate was issued by Let's Encrypt — issuer CN=YR1, serial 5fe3baf35c3534571f8e352115b86a4e57b — covering every possible subdomain of hhautoinvestment.co.tz, a Tanzanian-registered domain that had sat dormant since its registration on 24 August 2023.

    #AgentTesla#credentialharvesting#processhollowing#FTPexfiltration#ageddomaininfrastructure#manufacturing#healthcare#TanzaniaccTLD
    IOCf3 · i0 · d1 · u1MITRE47RegionsAE · DE · DK · JPIndustriesArts & Entertainment · Automotive · Business Associations
  • C&CMembersJun 18, 2026, 20:06 (UTC+9)

    Phorpiex Clipbanker Uses Six Greek-Letter C2 Endpoints to Steal Crypto

    A 103-kilobyte Windows executable named wescgsvcs.exe — crafted to blend visually with legitimate Windows service binaries — has been quietly draining cryptocurrency wallets through one of the more methodical evasion stacks CTX Team has documented in this family class. The binary, confirmed as a Phorpiex/Fragtor trojan with a clipbanker payload, beacons to a single command-and-control server at 185.215.113.84 that exposes exactly six HTTP endpoints named in Greek alphabetical order: alpha,…

    #Phorpiex#Fragtor#clipbanker#cryptocurrencytheft#command-and-controlinfrastructure#sandboxevasion#timestomping#clipboardhijacking
    IOCf4 · i1 · d0 · u7MITRE31
  • APTMembersJun 18, 2026, 15:58 (UTC+9)

    Forged 72-Hour Certificates Hid WarzoneRAT From All 76 AV Engines

    Seven Windows executables and DLLs, all signed under the name of a legitimate German digital-publishing company, arrived on VirusTotal on 23 May 2026 with a combined static detection score of zero across 76 engines. The files presented themselves as components of "t-online Browser 7," a real product distributed by Ströer Digital Publishing GmbH — complete with version strings, Mozilla Public License 2.0 copyright notices, and Authenticode signatures rooted in Microsoft's own…

    #APT28#WarzoneRAT#Winos4.0#Skip-2.0#code-signingabuse#energysector#GermanyFranceLuxembourg#Authenticode
    ActorsAPT28 · StrontiumIOCf55 · i0 · d0 · u0MITRE55RegionsDE · FR · LUIndustriesEnergy · Technology · Telecommunications
  • APTMembersJun 18, 2026, 04:04 (UTC+9)

    NullMixer Bundle Drops Five Malware Families via Discord Fake Installer

    A single Windows executable masquerading as a software setup wizard unpacks at least five distinct malware families the moment a user double-clicks it — RedlineStealer, ClipBanker, SmokeLoader, StealBit, and Upatre arriving as a coordinated bundle rather than a sequential chain. That delivery model, confirmed by the Malpedia YARA rule win_nullmixer_auto firing on two large installer files and by unanimous sandbox verdicts naming four families simultaneously, is the operationally distinctive…

    #APT28#NullMixer#RedlineStealer#SmokeLoader#ClipBanker#DiscordCDNabuse#Bolivia#fakeinstaller
    ActorsAPT28 · StrontiumIOCf18 · i3 · d4 · u10RegionsBO
  • APTMembersJun 17, 2026, 23:57 (UTC+9)

    DHL-Lure RAR Delivers MassLogger to Construction Firms Across Four Countries

    A 946-kilobyte RAR archive named DHL_AWB#6078538091.rar has been circulating since mid-May 2026 as the opening move in a credential-harvesting campaign targeting construction-sector organisations across Germany, India, Malaysia, and Turkey. The archive is not simply a container — it is itself the first evasion layer, carrying explicit debugger-detection and long-sleep logic that caused one major automated analysis platform to return a clean verdict at 96% confidence while a second correctly…

    #APT29#MassLogger#Formbook#credentialharvesting#constructionsector#sandboxevasion#spear-phishing#processinjection
    ActorsAPT29 · MinidionisIOCf3 · i0 · d0 · u0MITRE23RegionsDE · IN · MY · TRIndustriesConstruction
  • C&CMembersJun 17, 2026, 20:27 (UTC+9)

    Phorpiex Rotates All Payloads Again as C2 Holds Firm for Ninth Wave

    ##Phorpiex Swaps Its Entire Payload Stack — Again — While C2 Holds Firm for a Ninth Consecutive Wave Since earlier coverage documented the Phorpiex/Trik operator's discipline of rotating binaries while leaving command-and-control infrastructure untouched, that pattern has completed another full cycle. All three payload files present in this snapshot are new arrivals; all three files from the prior snapshot have been retired.

    #Phorpiex#Trik#payloadrotation#sandboxevasion#C2infrastructure#telecommunications#Kazakhstan#Pakistan
    IOCf3 · i2 · d0 · u4MITRE35RegionsKZ · PKIndustriesTelecommunications
  • APTMembersJun 17, 2026, 20:00 (UTC+9)

    Salat Stealer Bypasses Chrome v127 Encryption in Capability Leap

    A 12-megabyte unsigned Windows executable first observed on 2 May 2026 carries a capability set that goes well beyond what commodity stealers typically offer: a working Chromium app-bound encryption decrypter, a large embedded catalogue of cryptocurrency wallet browser-extension identifiers, and a command-and-control resolution path routed through Cloudflare's DNS-over-HTTPS service to defeat the DNS-layer monitoring that would otherwise expose its infrastructure.

    #SalatStealer#Chromiumapp-boundencryptionbypass#DNS-over-HTTPSevasion#credentialtheft#cryptocurrencywalletharvesting#APT28#CloudflareCDNabuse#browsercredentialstores
    ActorsAPT28 · StrontiumIOCf1 · i2 · d3 · u2MITRE11
  • APTMembersJun 17, 2026, 13:49 (UTC+9)

    APT10's 2016 ChChes Implant Runs on C2 Renewed in 2025

    A 283-kilobyte Windows executable compiled in November 2016 carries a code-signing certificate that expired more than a decade ago — yet the command-and-control domain it phones home to received a fresh TLS certificate as recently as September 2025. That tension between aged tooling and actively maintained infrastructure is the defining characteristic of a ChChes implant attributed to Red Apollo (APT10) that CTX Team has been tracking since December 2024.

    #RedApollo#APT10#ChChes#OperationCloudHopper#code-signingabuse#C2infrastructure#sandboxevasion#espionage
    ActorsRed Apollo · PotassiumIOCf1 · i0 · d1 · u5MITRE13
  • APTMembersJun 17, 2026, 13:31 (UTC+9)

    Scripted CKEditor Exploitation Endpoints Surface Across Two Campaign Domains

    Four newly documented URLs targeting the CKEditor-for-WordPress plugin across two domains — kartacnictvi.cz and mokawafm.com — now explicitly expose the scripted initial-access mechanism behind a campaign CTX Team has been tracking in connection with a Lazarus Group CRAT implant. Each URL follows the same path structure — wp-content/plugins/ckeditor-for-wordpress/ckeditor/plugins/image/ — and carries a hex-timestamp query parameter: ts=6A4310F7_1897026C, ts=6A431118_12AB12AC,…

    #LazarusGroup#CRAT#Nukesped#Zusy#WordPressCKEditor#Jordan#foodandbeverages#initialaccess
    ActorsLazarus Group · Hastati GroupIOCf2 · i2 · d2 · u6MITRE19RegionsJOIndustriesFood & Beverages
  • FILEMembersJun 17, 2026, 11:08 (UTC+9)

    Dormant Snapchat Lure Domain Wakes After 13 Months to Serve LummaStealer

    A domain registered in April 2025 under the guise of a Snapchat mod APK resource sat completely inactive for thirteen months before its operator flipped a switch in May 2026: a Let's Encrypt TLS certificate was issued, six numbered Windows executables appeared at predictable paths, and a social-engineering notes file went live alongside them.

    #LummaStealer#VenomRAT#QuasarRAT#credentialtheft#cryptocurrencywalletharvesting#Canada#Telegramexfiltration#domainaging
    IOCf9 · i0 · d1 · u8MITRE41RegionsCA
  • FILEMembersJun 17, 2026, 10:36 (UTC+9)

    GuLoader Hits EU Healthcare via Danish Temp Folder and Forged 2013 Timestamp

    A 673-kilobyte Windows executable with a Polish-language filename — Zamowienie_829522.bat, meaning "Order 829522" — is the entry point for one of the more technically deliberate GuLoader campaigns CTX Team has tracked against European healthcare targets. The file is a Nullsoft Installer self-extracting archive, flagged by 49 of 77 antivirus engines under the label trojan.makoob/nsis, and it arrives carrying a PE timestamp set to Christmas Day 2013 — a date approximately eleven years before the…

    #GuLoader#NSISdropper#healthcaresector#Poland#Croatia#JPEGsteganography#cPanelC2infrastructure#ransomwareprecursor
    IOCf16 · i1 · d2 · u2MITRE19RegionsHR · PLIndustriesHealthcare
  • APTMembersJun 17, 2026, 10:08 (UTC+9)

    TA505 Fake Purchase Order Hides JS Payload 70 Engines Cannot See

    A spear-phishing campaign attributed to TA505 is circulating a Varist-packed RAR archive named after a fake purchase order — but the real detection problem sits one extraction step deeper: the JavaScript payload inside evades 70 of 76 antivirus engines despite both sandboxes that processed it returning unambiguous malicious verdicts, and despite an Abuse.ch IDS rule already flagging its PureHVNC command-and-control certificate.

    #TA505#PureHVNC#JavaScriptdropper#spear-phishing#procurementsector#sandboxevasion#Unicodeobfuscation#dormantdomainreactivation
    ActorsTA505 · Hive0065IOCf2 · i0 · d1 · u2RegionsCY · DE · DK · FRIndustriesRetail · Support Services · Technology
  • APTMembersJun 17, 2026, 09:42 (UTC+9)

    XWorm V5.6 Deploys 18-Plugin Suite Behind Azure-Hosted C2 Fleet

    A complete, operationally ready XWorm V5.6 toolkit — nineteen files in total, comprising a main RAT executable and eighteen purpose-built plugin DLLs compiled from a single build pipeline — has been observed in active deployment, with the plugin suite spanning hidden VNC access, keylogging, browser credential theft, ransomware, CMSTP-based UAC bypass, and Windows Defender suppression.

    #GamaredonGroup#XWorm#HiddenTearransomware#HVNC#CMSTPUACbypass#credentialharvesting#Azureinfrastructureabuse#Ukraine
    ActorsGamaredon Group · CTIGIOCf43 · i0 · d9 · u18MITRE37RegionsBD · DE · GB · IN
  • C&CMembersJun 17, 2026, 08:34 (UTC+9)

    Stealc v2 Bypasses Chrome 127 Encryption in Crypto-Theft Campaign

    A financially motivated operator has deployed a multi-stage credential-theft campaign built around two Stealc v2 payloads that implement a post-Chrome-127 app-bound encryption key decryptor — a deliberate capability upgrade that allows the malware to extract browser-stored credentials from modern Chrome profiles that earlier Stealc variants and most competing infostealers cannot reach.

    #Stealcv2#DiamotrixClipper#Chromiumapp-boundencryptionbypass#reflectiveDLLinjection#clipbanker#bulletproofhosting#cryptocurrencytheft#infostealer
    IOCf11 · i5 · d0 · u10MITRE51RegionsCA
  • C&CMembersJun 17, 2026, 08:03 (UTC+9)

    Sality Botnet Hides C2 Traffic in GIF Requests Across Italian and Polish Hosts

    Twenty-four HTTP GET requests. Two geographically disparate web servers. One 5-kilobyte image file. On the surface, a routine web browser fetching a logo. Underneath, an active Sality botnet cluster routing encrypted bot check-ins through parameterised image requests to compromised shared-hosting accounts in Italy and Poland — a beaconing architecture that has been generating fresh C2 traffic into mid-2026 from a core payload first submitted to VirusTotal in July 2010.

    #Sality#SaltySpider#C2infrastructure#sharedhostingabuse#GIFsteganography#USBpropagation#Bangladesh#Tofsee
    ActorsSalty Spider · KuKuIOCf24 · i2 · d2 · u24RegionsBD
  • FILEMembersJun 15, 2026, 11:35 (UTC+9)

    WinosStager Loader Hides Behind Chrome, Routes All C2 Through Tor

    A 66,879-kilobyte Windows executable dressed as Google Chrome is circulating across chemicals, consulting, government, and manufacturing organisations in ten countries — and every byte of its command-and-control traffic flows exclusively through the Tor anonymity network to algorithmically generated .onion hidden services, leaving no clearnet address for network defenders to block, sinkhole, or pivot from.

    #WinosStager#CleverSoar#TorC2#Chromeimpersonation#compile-on-host#manufacturing#government#Skip-2.0
    IOCf23 · i0 · d2 · u0MITRE51RegionsGU · IN · IT · MYIndustriesChemicals · Consulting · Government
  • FILEPublicJun 15, 2026, 11:19 (UTC+9)

    APT1 Freeware Lure Still Active 12 Years On, Live Cert Reveals

    A 527-kilobyte Windows executable presents itself to the world as a routine archiving utility. Its internal product string reads "B1 Free Archiver Installer," its filename circulates as B1FreeArchiver_1.4.68.exe, and its copyright notice is dated 2013. None of that is what it is. Forty-three of 77 antivirus engines classify the binary as adware.catalina/downware — a trojanised installer that bundles unwanted payloads under a recognisable freeware brand — and three concurrent IDS rules confirm…

    #CommentCrew#APT1#adware.catalina#freewaremasquerading#content-typespoofing#educationsector#SouthAsia#glassesmalwarefamily
    ActorsComment Crew · Byzantine CandorIOCf4 · i1 · d0 · u0MITRE25RegionsSAIndustriesEducation & Research
  • APTMembersJun 15, 2026, 10:27 (UTC+9)

    BlueBottle Hides Cryptominer in Fake FileZilla Update Targeting DRC

    A typosquatted domain impersonating the FileZilla FTP client is serving a two-stage dropper-binder chain to targets in the Democratic Republic of Congo — an operation that pairs brand-impersonation lures with layered sandbox evasion baked into every executable stage, while beaconing to the hashvault.pro cryptomining pool over a CoinMiner JA3 TLS fingerprint.

    #BlueBottle#Opera1er#BitRAT#cryptomining#DemocraticRepublicofCongo#typosquatting#sandboxevasion#FileZillaimpersonation
    ActorsBlueBottle · Opera1erIOCf4 · i1 · d1 · u2MITRE18RegionsCD
  • APTMembersJun 15, 2026, 10:15 (UTC+9)

    TA511 Bundle Deploys StealC v2 With Chrome Encryption Bypass via Single German AS

    ##A Four-Family Payload Bundle Targets Browser Credentials and Crypto Wallets From a Single German Hosting Fabric A coordinated malware campaign deploying Amadey, StealC v2, LummaC2, and ClipBanker as a unified payload bundle has concentrated every observed command-and-control endpoint inside a single autonomous system — AS214351, operated by Femo It Solutions Limited — a RIPE NCC-registered provider that came into existence in October 2024 and whose IP space spans just two /24 subnets…

    #TA511#StealCv2#Amadey#ClipBanker#AS214351#Chromiumapp-boundencryptionbypass#credentialtheft#cryptocurrencyhijacking
    ActorsTA511 · MAN1IOCf33 · i3 · d0 · u6RegionsCLIndustriesTechnology
  • C&CMembersJun 14, 2026, 22:59 (UTC+9)

    Emotet C2 Hides Behind WordPress Paths on Aged Compromised Domains

    Two compromised websites — one a Turkish-language platform, the other a social media aggregator — are currently serving as active command-and-control relay nodes for an Emotet campaign cluster, with their WordPress administrative and content directories repurposed as beaconing endpoints. The infrastructure fingerprint CTX Team has documented is precise: dotasarim.com/wp-admin/Dyz and socialplaymedia.com/wp-content/Czj function as the actual C2 URLs, their paths indistinguishable at a glance…

    #Emotet#Emotetepoch2#TA542#WordPressC2#command-and-controlinfrastructure#macro-enabledlure#TimewebASN9123#compromisedwebsites
    ActorsEmotet Group · TA542IOCf3 · i1 · d2 · u4
  • APTMembersJun 14, 2026, 22:29 (UTC+9)

    KMSpico Campaign Adds 9 Variants, Core Four-Layer Evasion Stack Unchanged

    Nine new file indicators have surfaced in the Molerats-attributed KMSpico campaign since CTX Team's earlier coverage, expanding the known file set to 17 samples — yet not a single new network indicator has emerged alongside them. The delta is entirely on the file side, and the pattern shows an operator iterating the outer delivery shell while leaving the campaign's most distinctive technical architecture completely intact: a four-layer evasion stack built around a self-issued certificate…

    #Molerats#KMSpico#Formbook#WinDivert#Dotfuscator#code-signingabuse#technologysector#Malaysia
    ActorsMolerats · Gaza CybergangIOCf17 · i0 · d0 · u0MITRE19RegionsMYIndustriesTechnology
  • FILEPublicJun 14, 2026, 19:07 (UTC+9)

    Trojanized Black Myth: Wukong Launcher Delivers Rancor Trojan to Thai Users

    A 457-kilobyte Windows executable named "Launcher Black Myth Wukong.exe" is circulating in Thailand, masquerading as the Steam launcher for one of 2024's most widely played game titles — and carrying a Rancor-family trojan payload that 52 of 76 antivirus engines now flag as malicious while the Zenbox sandbox returns a clean verdict at 98% confidence. The gap between those two numbers is the story: the operators behind this campaign did not rely on a single evasion trick.

    #Snowglobe#AnimalFarm#Rancor#Babar#Thailand#gaminglure#sandboxevasion#espionage
    ActorsSnowglobe · Animal FarmIOCf3 · i0 · d1 · u0MITRE21RegionsTH
  • FILEPublicJun 14, 2026, 14:58 (UTC+9)

    Dual-Certificate PCHunter Stack Hits Finance and Telecom Across 14 Nations

    A VMProtect-packed, DigiCert EV-signed executable and a Microsoft WHQL-cross-signed kernel driver — both components of the PCHunter Windows inspection utility, both carrying certificates that expired years ago but were valid at the moment of signing — are circulating in active operations against financial services, technology, and telecommunications organisations across fourteen countries.

    #PCHunter#RoyalRansomware#WHQLdriverabuse#VMProtect#kernel-modedriver#financialservices#code-signingevasion#espionage
    ActorsRoyal Ransomware · Team OneIOCf3 · i0 · d0 · u0MITRE25RegionsAT · CA · CL · CNIndustriesFinancial Services · Technology · Telecommunications
  • C&CPublicJun 14, 2026, 14:39 (UTC+9)

    Phorpiex Worm's Three-Layer Evasion Stack Keeps 20 AV Engines Blind

    A 77-kilobyte Windows executable — small enough to be dismissed as a stub, old enough to have first appeared on VirusTotal in October 2020 — is still generating active C2-server feed hits as of mid-2026. The sample, carrying the threat label trojan.phorpiex/zard and the deceptively mundane meaningful name DriveMgr.exe, is not remarkable for its size or age alone.

    #Phorpiex#Zard#worm#packedPE#C2infrastructure#TLSevasion#MEVSPACE#Guatemala
    IOCf3 · i2 · d0 · u3MITRE34RegionsGT
  • APTMembersJun 14, 2026, 10:17 (UTC+9)

    APT27's Godzilla Loader Factory: 18 Cloned Binaries, One C2 Gate

    Nineteen PE32 executables. One YARA rule. Six .ru domains. A single PHP gate path with a campaign identifier that never changes. What CTX Team's analysis of this cluster reveals is not a hastily assembled intrusion kit but the output of a production-grade payload generation pipeline — one where 18 structurally identical 9 KB binaries are stamped from a single build toolchain, each mutated just enough at the byte level to carry a distinct fuzzy hash while preserving an identical PE import table,…

    #APT27#GodzillaLoader#PonyStealer#certificateabuse#C2infrastructure#Italy#payloadfactory#code-signingabuse
    ActorsAPT27 · TEMP.HippoIOCf28 · i0 · d24 · u12MITRE9RegionsIT
  • APTMembersJun 14, 2026, 06:29 (UTC+9)

    One Fake Certificate Signs 13 Pirated Windows Activation Tools

    Thirteen Windows binaries marketed under a dozen different brand names — AAct, KMSAuto Net, MSAct++, PIDKey Lite, KMSCleaner — all carry the identical self-issued code-signing certificate from an entity calling itself "WZTeam," serial E5 FA 25 47 0F 85 17 BF 41 52 87 01 4D AA 57 8C, thumbprint 87B3A6C360B37D6DB7F970DD1DC0009FBBD13BA0.

    #APT27attributionmismatch#crack-toolecosystem#KMSAutoKMSpicoAAct#code-signingcertificateabuse#Formbookanti-hookYARA#WindowsDefenderbypass#piratedsoftwaresupplychain#hacktoolPUAclassification
    ActorsAPT27 · TEMP.HippoIOCf51 · i0 · d0 · u0MITRE37RegionsHR · IN · PL · SIIndustriesEducation & Research · Hospitality & Leisure
  • FILEMembersJun 14, 2026, 03:28 (UTC+9)

    Thailand Telco Trojan Hides Banking Payload Inside Fake IDM Crack

    Somewhere between a piracy forum and a Thai telecom workstation, a 59-kilobyte executable named IDM_6.4x_Crack_v19.7.exe is doing something its would-be users never expected: running a layered evasion gauntlet that defeats at least one automated sandbox entirely before handing off to a 12-megabyte dropper that quietly installs a banking-capable payload, establishes registry persistence, and then erases itself from disk.

    #xegumumune#bankingtrojan#Thailand#telecommunications#sandboxevasion#WMIexecution#piracylure#C2infrastructure
    IOCf20 · i1 · d1 · u0MITRE47RegionsTHIndustriesTelecommunications
  • C&CMembersJun 14, 2026, 02:57 (UTC+9)

    Two Ghost Payloads Blind Analysts as Emotet Relay Cluster Holds Steady

    Since CTX Team's earlier coverage of this Emotet C2 cluster — documented in the prior article tracking the campaign's 89-day Let's Encrypt rotation pattern — two new file samples have entered the payload layer with zero VirusTotal enrichment: no file type, no detection ratio, no behavioural tags, no signer data. The infrastructure they connect to is unchanged and already fingerprinted. The payloads themselves are, at this moment, analytically invisible.

    #Emotet#TA542#MummySpider#C2infrastructure#Let'sEncryptcertificaterotation#WordPressrelay#payloadcycling#Romania
    ActorsEmotet Group · TA542IOCf3 · i1 · d3 · u4RegionsRO
  • C&CMembersJun 14, 2026, 02:41 (UTC+9)

    Emotet-Labeled Loader's TLS Handshake Trips Dridex IDS Rules

    A Win32 loader DLL tracked in this cluster — 65 of 77 engines flag it, and Zenbox, VMRay, and C2AE all name it Emotet in a unanimous 3/3 sandbox verdict — trips two independent intrusion-detection rules built for an entirely different crimeware family. The DLL's outbound TLS handshake fires "ET JA3 Hash - [Abuse.ch] Possible Dridex" from Proofpoint's Emerging Threats Open ruleset and a second hit from Abuse.ch's SSLBL malicious JA3 fingerprint list, also tagged Dridex.

    #Emotet#Dridex#JA3fingerprint#Excel4macromaldoc#loaderDLL#TA542#commodityhostinginfrastructure#sandbox-evasion
    ActorsEmotet Group · TA542IOCf4 · i3 · d2 · u7RegionsRO
  • APTMembersJun 14, 2026, 02:27 (UTC+9)

    Dormant Domain Reactivated With Fresh Cert to Power Backdoor C2

    A domain registered in December 2019 and left parked behind ad-network nameservers for more than six years quietly received a new, short-lived TLS certificate on September 1, 2025 — and within weeks was hosting a live-looking command-and-control subdomain. The domain, wthelpdesk.com, is the single richest piece of evidence in this record, and it tells a story less about a specific actor than about how patiently some operators are willing to season their infrastructure before switching it on.

    #RedApollo#APT10#ChChes#CloudHopper#domainparking#Let'sEncryptcertificateabuse#backdoormalware#XORobfuscation
    ActorsRed Apollo · PotassiumIOCf1 · i0 · d1 · u5RegionsDE
  • APTMembersJun 14, 2026, 02:14 (UTC+9)

    Fake KMS Activators Share One Untrusted Signing Certificate

    Two Windows executables masquerading as pirated-software tools — one branded "KMSAuto++.exe," the other disguised as an "Office 2013-2021 C2R Install Lite" installer — are circulating with an identical, untrusted code-signing certificate stamped by an entity calling itself WZTeam. The certificate, serial 8A C1 A3 10 13 49 C2 8A 4D 33 94 7C FC D0 76 62, terminates in a root that Windows does not trust, yet it appears verbatim across both binaries, alongside a shared VirusTotal family label of…

    #KMSAuto#code-signingcertificateabuse#UPXpacking#PowerShelldownloader#piratedsoftwaredistribution#APT27#njRAT#maliciousdomaininfrastructure
    ActorsAPT27 · TEMP.HippoIOCf16 · i0 · d2 · u2MITRE53RegionsTHIndustriesTelecommunications
  • C&CMembersJun 13, 2026, 14:47 (UTC+9)

    BazLoader, Amadey, and StealC V2 Chain Targets Algeria and Italy via Single German /24

    A 170-kilobyte PE32 dropper first submitted to public scanning infrastructure on 12 June 2026 is the entry point for one of the more operationally compact espionage-oriented loader chains CTX Team has tracked this quarter. The binary — identified as BazLoader/egairtigado and observed in the wild as sprd2.exe — touches down in the user Temp directory, copies itself to C:\Windows\8amu8dw.exe, and immediately begins beaconing over raw IPv4 HTTP to a pair of hosts consolidated within the…

    #BazLoader#Amadey#StealCV2#WoodyRAT#AS214351#credentialharvesting#Algeria#Italy
    IOCf30 · i2 · d0 · u5MITRE62RegionsDZ · IT
  • C&CMembersJun 13, 2026, 14:32 (UTC+9)

    woody_rat Stealer Drains Exodus and ElectronCash Wallets via Telegram Log Market

    ##Wallet Vaults Cracked Open: How a woody_rat Infostealer Pipeline Drains Exodus and ElectronCash in a Single Pass A woody_rat operation tracked by CTX Team has been systematically dismantling the cryptocurrency holdings of technology-sector victims in Egypt and Hungary, harvesting the full wallet store of both Exodus and ElectronCash installations in a single automated sweep — then packaging the stolen files into dated log archives and routing them through a Telegram bot channel for downstream…

    #woody_rat#infostealer#Exoduswallet#ElectronCash#Telegramlogmarket#cryptocurrencytheft#Egypt#Hungary
    IOCf68 · i2 · d0 · u3MITRE62RegionsEG · HUIndustriesTechnology
  • C&CPublicJun 13, 2026, 10:39 (UTC+9)

    Fake Android Toolkit Delivers Sandbox-Proof Python Spyware

    A self-extracting RAR archive named "Android Win Tool v1.9.6" is circulating as a trojanized utility lure, staging a PyInstaller-packed Python trojan and a secondary unsigned PE payload that beacon to parameterized HTTPS endpoints across a purpose-built two-tier command-and-control infrastructure. The campaign — tracked by CTX Team under threat record CTXkz7eez4uc5 with severity 100 and confidence 85 — is distinguished not by any single technique but by the deliberate layering of evasion…

    #PyInstallertrojan#sandboxevasion#espionage#C2infrastructure#SFXarchivelure#Androidtoolkitlure#Let'sEncryptautomation#spyware
    IOCf26 · i2 · d3 · u3
5
Of10
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.