C&CPublicJun 13, 2026, 10:27 (UTC+9)Phorpiex Relay Cluster Exposed by Misplaced TLS Certificate on Spam Domain
Five mail-themed domains provisioned across two registrar accounts, a freshly compiled 18 KB loader carrying an XOR-obfuscated C2 address, and a TLS certificate whose subject field names a spam-trap tracking domain — together these artefacts paint a Phorpiex spam botnet operation whose infrastructure cohesion is unusually legible.
#Phorpiex#spambotnet#mailrelayinfrastructure#TLScertificateanomaly#XORobfuscation#domainregistration#C2servers#HondurasKyrgyzstanUnitedStatesIOCf4 · i4 · d54 · u1RegionsHN · KG · US
FILEMembersJun 13, 2026, 06:59 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Credential-Theft Campaign Across 7 Countries
Since CTX Team's earlier coverage of a trojanized CorelDraw crack campaign targeting Brazil, two new file samples have surfaced that confirm the operator is not winding down — they are building out. The most recent addition carries a PE compilation timestamp of 2026-05-08 and was first submitted to VirusTotal just three days later, on May 11.
#InjectorNett#PureLogs#WinRing0x64BYOVD#LOLDrivers#cryptomining#credentialtheft#AS213010#NICENICinfrastructureIOCf7 · i2 · d3 · u4MITRE58RegionsAU · BD · BR · ESIndustriesConstruction · Hospitality & Leisure · Manufacturing
APTMembersJun 13, 2026, 02:32 (UTC+9)WHQL-Signed Kernel Driver With 2/76 Detections Opens Stealc v2 Kill Chain
A 34-kilobyte Windows kernel driver signed by the Microsoft Windows Hardware Compatibility Publisher — carrying a WHQL certificate chain that traces back to Microsoft's own root authority — is being deployed as the opening move in a five-stage financial-theft campaign that ultimately delivers Stealc v2 credential stealers capable of bypassing Chromium app-bound encryption and in-process clipboard hijackers targeting cryptocurrency wallet addresses.
#WizardSpider#Stealcv2#BYOVD#Amadey#clipboardhijacker#Chromiumapp-boundencryption#AS214351#kerneldriverabuseActorsWizard Spider · Grim SpiderIOCf11 · i3 · d1 · u5MITRE71RegionsAR · DE · IN · NG
FILEMembersJun 12, 2026, 22:44 (UTC+9)Sefnit C2 URI Unchanged for a Decade as Campaign Hits Thai Telecoms
A single line of HTTP traffic — gettasks.php?protocol=0&protoversion=201&o=0&p=C:%5CUsers%5Cadmin%5CAppData%5CLocal%5CTemp%5Cexplorer.exe&f=7296000 — appears identically across four command-and-control domains whose registration dates span more than a decade, from a domain created in July 2013 through to one registered in January 2024.
#Sefnit#Graftor#CeeInject#telecommunicationsservices#Thailand#processmasquerading#registrardiversification#command-and-controlinfrastructureIOCf3 · i1 · d4 · u12MITRE26RegionsTHIndustriesTelecommunications
FILEMembersJun 12, 2026, 07:28 (UTC+9)'mixseven' Affiliate Deploys Six Malware Families via Single PPI Tag
A single pay-per-install affiliate operating under the publisher tag pub=mixseven has coordinated the simultaneous deployment of at least six distinct malware families — GCleaner, SmokeLoader, PrivateLoader, Socelars, Fabookie, RedLine Stealer, FFDroider, and Glupteba — through a layered loader chain whose network infrastructure was provisioned in a single automated session in September 2021.
#mixseven#pay-per-install#GCleaner#SmokeLoader#RedLineStealer#Glupteba#credentialharvesting#PPIaffiliatenetworkActorsSmoky Spider · BariumIOCf20 · i5 · d2 · u13MITRE64
APTMembersJun 12, 2026, 06:42 (UTC+9)Emotet OCX Loader Beacons to Four Continents via regsvr32 Proxy
A 64-bit Windows DLL masquerading as an OLE Control Extension file — delivered under the name hvxda.ocx and designed to run through regsvr32 rather than a conventional executable launcher — sits at the centre of an active Emotet deployment that has been beaconing to four geographically dispersed command-and-control servers across Malaysia, Ghana, Germany, and South Korea.
#Emotet#TA542#Dridex#regsvr32proxyexecution#multi-epochC2infrastructure#bankingtrojan#GeorgiaandQatartargeting#FeodoTrackerActorsEmotet Group · TA542IOCf1 · i4 · d0 · u7MITRE21RegionsGE · QA
FILEMembersJun 12, 2026, 03:25 (UTC+9)Trojanized CorelDraw Crack Hits Brazil With Four-Payload Attack Chain
A trojanized CorelDraw activation archive that has reached 887 unique submitters since March 2025 is deploying a layered attack chain against Brazil's construction, hospitality, media, and retail sectors — one that combines a PureLogs credential stealer, an embedded coin-miner, a three-stage hosts-file poisoning sequence, and a Bring Your Own Vulnerable Driver (BYOVD) component borrowed from a 2008-era kernel driver.
#PureLogs#BYOVD#WinRing0x64.sys#coin-miner#Brazil#piratedsoftwaredistribution#credentialtheft#AS213010IOCf17 · i2 · d3 · u4MITRE72RegionsBRIndustriesConstruction · Hospitality & Leisure · Media
FILEPublicJun 11, 2026, 23:43 (UTC+9)WarzoneRAT Invoice Lure Layers Anti-Analysis Stack Against Turkish Targets
A 2,695-kilobyte Windows executable, packaged under the filename Invoice.exe and built inside a commercial crypter environment, carries one of the more deliberately constructed anti-analysis stacks CTX Team has documented in a commodity remote-access trojan deployment: timing-based sandbox evasion, debugger detection, reflective code loading, process injection, UAC bypass, and an aggressive indicator-removal suite — all wrapped in a TLS-encrypted C2 channel that hides behind a hostname…
#GoldEvergreen#WarzoneRAT#AveMaria#Turkey#sandboxevasion#UACbypass#invoicephishing#C2infrastructureActorsGold Evergreen · Business ClubIOCf1 · i0 · d2 · u0MITRE21RegionsTR
FILEMembersJun 11, 2026, 19:41 (UTC+9)OceanLotus Hid Denis Backdoor Behind Forged Microsoft Identity and DNS Tunnel
Two Win32 executables compiled on the same December afternoon in 2015 represent something more instructive than their age might suggest: a precisely engineered deception stack in which every layer — binary identity, code-signing posture, execution behaviour, and network communications — was designed to pass as something legitimate. Both are Denis backdoor variants attributed to OceanLotus (also tracked as APT32, Canvas Cyclone, and Bismuth).
#OceanLotus#APT32#Denisbackdoor#DNStunnelling#code-signingforgery#sandboxevasion#binarymasquerading#SoutheastAsiaespionageActorsOceanLotus · APT32IOCf2 · i0 · d2 · u0MITRE12RegionsCN
C&CMembersJun 11, 2026, 19:10 (UTC+9)Twenty IPs, One Certificate: How a Phorpiex C2 Pool Mimics 2345.com
Eight of the twenty IP addresses flagged as command-and-control infrastructure for a financially motivated operation tracked under the phorpiex family sit inside a single China Telecom autonomous system, AS4811 — and five of those nodes present an identical TLS certificate, serial d3d9e9261c1c88d957e704d69617a469, whose subject reads *.2345.com.
#Phorpiex#C2infrastructure#TLScertificatereuse#ChinaTelecomAS4811#2345.comspoofing#adware/PUAinstaller#sslTrusCA#financiallymotivatedthreatactorIOCf3 · i27 · d0 · u0MITRE20RegionsCN
FILEMembersJun 11, 2026, 16:10 (UTC+9)2345Pinyin IME Runs Six-Year Covert Delivery Pipeline Behind Ad-Injection Cover
A Chinese-language input method editor has been quietly running a multi-tier asset-delivery pipeline on victim hosts since at least 2018 — one whose technical fingerprints look considerably more sophisticated than the advertisement injection it ostensibly exists to perform. The 2345Pinyin IME client, distributed by Shanghai 2345 Network Technology Co., Ltd.
#2345NetworkTechnology#2345Pinyin#adware#PUA#HongKong#mediasector#CDNabuse#indicatorremovalIOCf44 · i5 · d0 · u0MITRE24RegionsHKIndustriesMedia
C&CMembersJun 11, 2026, 15:27 (UTC+9)Amadey Stealer Runs 67-IP C2 Pool Engineered to Outlast Blocklists
Sixty-seven IP addresses. One stealer binary. And an infrastructure architecture so deliberately fragmented that no single takedown pathway touches more than a fraction of it. That is the operational picture CTX Team has assembled around a currently active Amadey stealer deployment — a campaign whose most distinctive feature is not the malware itself but the tiered, multi-continent command-and-control fabric the operators have constructed around it.
#Amadey#stealer-as-a-service#C2infrastructure#KoreaTelecomAS4766#Let'sEncryptcertificaterotation#Brazilacademicnetwork#credentialharvesting#processinjectionIOCf1 · i67 · d0 · u2MITRE30
C&CMembersJun 11, 2026, 14:58 (UTC+9)MSIL/Bobik Dropper Stays Live as Mystery Second File Hints at New Payload
A 982-kilobyte unsigned .NET assembly — its PE timestamp deliberately forged to the year 2085 to confound timeline-based triage, its primary code section packed to an entropy of 7.64 — has been confirmed active as recently as 23 June 2026, deploying an XMRig-compatible cryptocurrency miner and PureLog credential stealer simultaneously to compromised endpoints across six industry verticals and 42 countries.
#MSIL/Bobik#PureLogStealer#XMRig#Contaboinfrastructure#credentialtheft#cryptocurrencymining#packed.NETdropper#multi-countrytargetingIOCf2 · i1 · d0 · u3MITRE37RegionsAR · AT · AU · BEIndustriesCommercial Services · Education & Research · Government
APTMembersJun 11, 2026, 14:40 (UTC+9)Same-Day Certificates Expose Scripted C2 Build-Out Behind Two Trojans
Three infrastructure nodes — the IPs 31.58.134.74 and 80.97.160.31, plus the freshly minted domain powershell-storage.vg — received Let's Encrypt certificates from the same "YE2" intermediate within a two-day window in June, each carrying an identical 89-day validity span. That kind of synchronized issuance is not how organically managed hosting behaves; it is what scripted infrastructure provisioning looks like when an operator wants a C2 front live and disposable within hours of registering…
#APT28#NICENIC#Let'sEncryptcertificates#DNSPod#C2infrastructure#codesigningabuse#installertrojans#domainregistrationclusterActorsAPT28 · StrontiumIOCf7 · i4 · d5 · u6RegionsID · MY · PL
APTPublicJun 11, 2026, 14:25 (UTC+9)Shell Crew's Zero-Detection C2 and Anti-Forensic Toolkit Hit Mexico Construction
Five hacktools attributed to Shell Crew — the Chinese state-aligned intrusion set also tracked as Deep Panda, APT26, Turbine Panda, and Checkered Typhoon — have been linked to an active espionage campaign targeting Mexico's construction sector, with a command-and-control node on China Unicom's commercial backbone that registered zero detections across 91 VirusTotal engines despite carrying a named-actor attribution.
#ShellCrew#DeepPanda#terracotta_vpn#Mexicoconstructionsector#ChinaUnicomAS-4837#anti-forensictradecraft#credentialdumping#C2infrastructureActorsShell Crew · WebMastersIOCf5 · i1 · d0 · u0MITRE28RegionsMXIndustriesConstruction
C&CMembersJun 11, 2026, 10:46 (UTC+9)Dutch VPS and Borrowed ISP Relays Power Ranapama Infostealer C2
A Let's Encrypt certificate minted on 29 January 2026 for the domain aceinco.com — valid for exactly 89 days, hosted on a LeaseWeb Netherlands VPS at 85.17.31.111 (AS60781) — is the clearest fingerprint of operator-controlled infrastructure in a 57-IP command-and-control network assembled around the ranapama infostealer. Everything else in the observable pool appears to be borrowed: compromised Korea Telecom broadband endpoints, hijacked subscriber lines on a Belarusian mobile carrier, and at…
#ranapama#infostealer#commandandcontrol#LeaseWeb#KoreaTelecom#SOHOroutercompromise#credentialharvesting#processinjectionIOCf1 · i57 · d0 · u0MITRE30
FILEMembersJun 11, 2026, 06:43 (UTC+9)XRed RAT Hits Peru Gov With Frozen 2019 Builder, AnyDesk Lures
Three Windows executables masquerading as a Synaptics touchpad driver and AnyDesk remote-desktop installer are circulating against Peruvian government targets, carrying an XRed RAT payload whose compiled import table has not changed since at least June 2019. The same imphash — 332f7ce65ead0adfb3d35147033aabe9 — locks together samples whose first VirusTotal submissions span four years, from June 2019 through October 2023, and the campaign was still active as recently as May 2026.
#XRedRAT#DarkKomet#Peruviangovernment#FreeDNSC2#sandboxevasion#espionage#commodityRAT#LatinAmericaActorsCactus · Cactus Ransomware GroupIOCf14 · i1 · d0 · u0MITRE20RegionsPEIndustriesGovernment
FILEPublicJun 11, 2026, 02:57 (UTC+9)Trojanised KMSAuto Delivers SmokeLoader via Three-Layer Evasion Stack
A trojanised Windows activation tool distributed through a software-piracy hosting path has been confirmed as the delivery vehicle for SmokeLoader, with the full infection chain relying on a deliberately engineered evasion stack — AutoIT compilation, aPLib decompression, UPX runtime packing, and active sandbox-fingerprinting — that goes well beyond what commodity pirated-software distributors typically invest in concealment.
#SmokySpider#SmokeLoader#AutoIT#aPLib#UPXpacking#sandboxevasion#Mongolia#softwarepiracylureActorsSmoky SpiderIOCf3 · i0 · d0 · u0MITRE28RegionsMN
FILEMembersJun 11, 2026, 02:44 (UTC+9)Autodesk Licensing Agent Hijacked to Drop Coinminer via DLL Sideload
A trojanized crack package impersonating Autodesk's Network License Manager is exploiting the legitimate AdskLicensingAgent service to load attacker-controlled code — a DLL sideload [T1574.002] that turns a trusted enterprise software component into an unwitting execution vehicle. The lure is polished enough to have drawn 461 submissions from 417 unique sources since late March 2026, and the campaign's evasion layer is effective enough that one major automated sandbox rated the primary payload…
#DLLsideloading#coinminer#AutodeskNetworkLicenseManager#AS213010#Brazilcontainersandpackaging#T1574.002#sandboxevasion#ParentLock.exeIOCf13 · i2 · d2 · u0MITRE53RegionsBRIndustriesContainers & Packaging
FILEMembersJun 10, 2026, 23:07 (UTC+9)Validly Signed uTorrent Installer Hides Trojanized Adware Payload
A Windows installer carrying a fully valid BitTorrent Inc / DigiCert code-signing chain is circulating as a trojanized uTorrent Classic setup — flagged malicious by 22 of 76 antivirus engines even though every certificate check in the chain returns clean. The same build lineage produced an unsigned, PEiD-packed sibling that only 4 of 75 engines catch.
#uTorrentimpersonation#code-signingabuse#TLScertificatespoofing#adware#offercore#inoci#myqcloud.comCDNimpersonation#PUAdistributionIOCf26 · i6 · d2 · u0RegionsAE · AL · AR · ATIndustriesCommercial Services · Education & Research · Hospitality & Leisure
C&CMembersJun 10, 2026, 14:56 (UTC+9)Five Unrelated Domains Share One 89-Day Certificate Fingerprint
Five infrastructure nodes with no obvious business relationship to one another — the domains resolvent.net, bvwebdesign.nl, platynum.ch and sjd.se, plus the bare IP 135.125.247.10 — all carry a Let's Encrypt TLS certificate with an identical 89-day validity span, and all five were issued within a six-week window between April 22 and June 8, 2026.
#c2infrastructure#Let'sEncryptcertificateautomation#Netskyworm#domainreactivation#TLScertificatefingerprinting#resellerhostingabuse#threatintelligencefeed#SMTPmass-mailerIOCf11 · i7 · d5 · u0MITRE22RegionsNZ
C&CMembersJun 10, 2026, 13:03 (UTC+9)Phorpiex Swaps Three Payloads While C2 Infrastructure Holds Firm
Three new PE32 executables have entered the Phorpiex botnet's active file set while three prior payloads were simultaneously retired — a clean swap that leaves the campaign's command-and-control backbone untouched for the eighth consecutive observation window. The rotation is surgical: the two C2 IP addresses, the wildcard certificate architecture anchored to *.certsdom.com, and the staging URL pattern under tsrv2.top all persist unchanged, while the operator pushes fresh binaries through the…
#Phorpiex#emailworm#botnet#Pakistan#telecommunications#payloadrotation#C2infrastructure#sandboxevasionIOCf3 · i2 · d0 · u4MITRE33RegionsPKIndustriesTelecommunications
APTMembersJun 10, 2026, 10:17 (UTC+9)Emotet DLL Poses as Chinese AV, Beacons to Five-ASN C2 Pool
A 572-kilobyte Windows DLL is circulating across healthcare networks in Panama wearing the identity of a Chinese-language antivirus product — its PE version-info fields stamped with the product name "MJAntiVirus.EXE," an internal name of "MJAntiVirus," and a copyright string reading "版权所有 (C) 2009." The file is unsigned, packed with PEiD, and carries a .rsrc section registering entropy at 7.75. It is, by unanimous verdict of six independent sandboxes, Emotet.
#Emotet#Dridex#TA542#healthcaresector#Panama#C2infrastructure#TLSfingerprinting#PEmasqueradingActorsEmotet Group · TA542IOCf1 · i5 · d0 · u9MITRE26RegionsPAIndustriesHealthcare
FILEMembersJun 10, 2026, 07:34 (UTC+9)Allaple Worm Hijacks 20 German Business Servers as Silent C2 Relays
Twenty static IP addresses, all assigned to small German businesses on Deutsche Telekom AG's T-DSL Business service, all falling within the same RIPE-registered netblock — 217.86.128.0 through 217.86.255.255, designated DTAG-STATIC02 — form the operational backbone of an Allaple worm campaign that CTX Team has tracked from February through June 2026. None of the twenty endpoints carry a single malicious detection across 91 scanning engines on VirusTotal.
#Allaple#DeutscheTelekomAS3320#compromisedSMBinfrastructure#C2relaynetwork#sandboxevasion#wormpropagation#Germanbusinessservers#retailsectortargetingIOCf41 · i29 · d0 · u0MITRE25RegionsUSIndustriesRetail
C&CMembersJun 10, 2026, 06:49 (UTC+9)LummaStealer Adds Isolated .qpon Node and 20 Hashes as Proton66 Cluster Holds
Since CTX Team's earlier coverage of this LummaStealer campaign, the operator has added twenty new file hashes to the payload catalog and provisioned a structurally distinct second domain — recenjc.qpon — that sits entirely outside the tight infrastructure cohort binding the original eight command-and-control nodes. The earlier coverage documented a remarkably coherent C2 fabric: eight pseudo-random seven-character hostnames under the Soviet-era .su TLD, all batch-registered on a single day,…
#LummaStealer#Proton66#C2infrastructure#credentialtheft#Spain#bulletproofhosting#malware-as-a-service#TraefikmisconfigurationIOCf20 · i1 · d9 · u17MITRE38RegionsES
APTMembersJun 10, 2026, 06:38 (UTC+9)One Expired Microsoft Cert Ties Three Amadey Dropper Stages Together
Five Windows executables — two trojanised KMS software-activation tools, two dedicated AV-killing binaries, and a fully operational Amadey bot loader — form a tightly bound dropper chain whose most distinctive feature is not the payload at the end but the build discipline that assembles it. A single expired Microsoft Windows Publisher leaf certificate, serial 33 00 00 02 4B B2 23 0A 43 CD 03 63 62 00 00 00 00 02 4B, has been stamped across three distinct malware stages with an identical signing…
#Amadey#KillAV#PS2EXE#KMSlure#certificateabuse#piracydistribution#RussiaC2infrastructure#dropperchainIOCf9 · i1 · d0 · u3MITRE31RegionsZW
APTMembersJun 9, 2026, 23:05 (UTC+9)APT28-Linked Loader Fires Amadey Signatures Despite DCRat Tag
A single Win32 executable now under continued watch by CTX Team carries three contradictory identities at once: the feed classifies it under the DCRat family, VirusTotal's own engines settle on the threat label "trojan.abmrisk/common," and the network traffic it generates fires Snort signatures written specifically for Amadey.
#APT28#Amadey#DCRat#loadermalware#commandandcontrol#Pleskauto-certificate#OmegatechLTD#codesigningevasionActorsAPT28 · StrontiumIOCf2 · i1 · d0 · u1MITRE25RegionsBD · BF · BR · DZIndustriesTechnology
FILEMembersJun 9, 2026, 20:32 (UTC+9)TA505 Dropper Sleeps Past Sandboxes, Stages Rockloader in 24 Countries
A roughly one-megabyte JavaScript file — encoded in UTF-16 little-endian, packed by Varist, and bearing filenames that mimic business invoice PDFs — is circulating across engineering, healthcare, manufacturing, legal, technology, and telecom organisations in 24 countries, functioning as the first stage of a delivery chain that culminates in the download of a Windows executable attributed to the rockloader family.
#TA505#rockloader#JavaScriptdropper#sandboxevasion#spear-phishing#invoicelure#everycarebd.com#espionageActorsTA505 · Hive0065IOCf38 · i0 · d1 · u3RegionsAE · AT · AZ · BDIndustriesEngineering · Healthcare · Manufacturing
C&CMembersJun 9, 2026, 19:37 (UTC+9)Dual-TLD DGA Gives Kazakhstan Ransomware Campaign Sinkhole-Resistant C2
Eighteen command-and-control domains generated by a single deterministic algorithm — split evenly across .ru and .su top-level domains, each carrying an identical 15-character vowel-heavy label structure — form the backbone of a financially motivated ransomware-adjacent campaign targeting Kazakhstan. The architecture is deliberate: by producing parallel domain sets from a common seed, the operator has engineered a C2 layer where sinkholing the .ru cluster leaves the structurally identical .su…
#trojan.bitmin/razy#domaingenerationalgorithm#Kazakhstan#dual-TLDC2#UPXpacking#TLSmasquerade#removablemediapropagation#ransomwareIOCf3 · i2 · d18 · u20MITRE39RegionsKZ
FILEMembersJun 9, 2026, 16:21 (UTC+9)Old Baixaki Typosquat Cluster Resurfaces via Unrelated 2026 CDN Certificate
Three subdomains built around the name of Brazil's largest freeware portal, all registered on the same day in October 2012 through PDR Ltd. d/b/a PublicDomainRegistry.com, have re-entered current threat telemetry paired with an unrelated certificate observation on a commercial Brazilian CDN more than a decade later — a pairing that illustrates how stale infrastructure and fresh re-observation timestamps can be mistaken for a live campaign if analysts don't check the dates.
#dealply#Baixakityposquat#AzionTechnologies#GlobalSigncertificate#adware/PUPdistribution#Brazil#staleIOC#VirtualDJinstallerlureIOCf7 · i2 · d3 · u1MITRE33RegionsBRIndustriesConsulting
APTMembersJun 9, 2026, 11:38 (UTC+9)IPFS Gateway Joins APT28-Linked C2 Stack Spanning Three Autonomous Systems
Two new IP addresses have been added to the infrastructure footprint of a delivery campaign that has been circulating trojanised installers and adware components since at least September 2025 — and one of them points somewhere unusual. IP 209.94.90.1, now part of the campaign's network layer, sits within ASN 40680, the address space operated by Protocol Labs, the organisation behind the InterPlanetary File System.
#APT28#IPFSabuse#PremierOpinionadware#code-signingcertificateabuse#DLLsideloading#technologysectortargeting#bulletproofhosting#trojanisedinstallersActorsAPT28 · StrontiumIOCf4 · i3 · d4 · u0MITRE13IndustriesTechnology
FILEMembersJun 9, 2026, 08:22 (UTC+9)Fake 'Sanwhole' Cert Anchors Layered Crypto-Wallet Heist via Trojanised IDE
A trojanised installer impersonating the developer tool "Netpas DevStudio" has been circulating with a self-fabricated code-signing certificate — issued by and to a fictitious entity called "Sanwhole" — whose chain terminates in an untrusted root that no legitimate certificate authority ever vouched for. Three files in the bundle carry the same fraudulent signature, the same certificate serial (26 F4 9B CA 07 79 1C 96 48 EA 3D 5A EA 7F 69 37), and the same thumbprint…
#Cryptbot#EmotetGroup#code-signingabuse#cryptocurrencywallettheft#developertoollure#sandboxevasion#infostealer#DLLspoofingActorsEmotet Group · TA542IOCf30 · i0 · d1 · u2MITRE39RegionsCI
C&CMembersJun 9, 2026, 07:51 (UTC+9)Same Cert Cadence Links Phishing Site to Domain Farm
Three domains that have nothing else in common — a Spanish site already flagged for phishing, and two hosts sitting under a fifteen-year-old apex — were all issued Let's Encrypt certificates through the identical "YR2" intermediate, with identical 89-day validity windows opened within a nine-day span. lavers.es, which alphaMountain.ai categorizes as Phishing, picked up a YR2 certificate valid 2026-06-05 through 2026-09-03. treddle.nuronapp.com got one valid 2026-05-29 through 2026-08-27.
#Let'sEncryptcertificateabuse#domainfarming#wildcardSANexposure#PUAdownloader#revokedcode-signingcertificate#multi-ASNinfrastructure#phishing#trojanizedsoftwareupdaterIOCf2 · i5 · d7 · u0MITRE12IndustriesTelecommunications
APTMembersJun 9, 2026, 07:24 (UTC+9)Void Arachne Hides DBatLoader Inside Fake FitGirl Game Repack Targeting Brazil
Two unsigned PE32 executables — both carrying the version metadata "product: 007 First Light / copyright: FitGirl" — have been circulating through pirated-software distribution channels targeting Brazilian users, wrapped inside a structurally complete fake game repack that bundles a Play.bat launcher, a game cover image, a convincing uninstaller, and a counterfeit DirectX installer to defeat automated sandbox analysis.
#VoidArachne#DBatLoader#Banload#Brazil#gamerepacklure#sandboxevasion#Russianhostinginfrastructure#initialaccesstrojanActorsVoid Arachne · Silver FoxIOCf17 · i4 · d2 · u0RegionsBR
FILEPublicJun 9, 2026, 04:10 (UTC+9)Football Manager 26 Crack Hides Two-Year-Old AutoIT Kill Chain
Since CTX Team's earlier coverage of this campaign, nine additional file indicators have surfaced, deepening the tooling picture around a multi-stage infection chain that pairs trojanized game installers with a layered evasion stack that has remained structurally intact across at least two years of active operation. The newest sample — a 20.6 MB executable named fm.exe carrying Unity Technologies copyright metadata and the embedded path C:\Games\Football Manager 26\fm.exe — represents the…
#Patchwork#APT-C-09#AutoIT#XMRig#BYOVD#WinRing0#cryptomining#LOLDriversActorsPatchwork · ChinastratsIOCf18 · i0 · d0 · u0MITRE45
C&CMembersJun 9, 2026, 03:58 (UTC+9)One GlobalSign Certificate Anchors 20 Malicious Files in Chinese Utility Trojan Campaign
A GlobalSign code-signing certificate issued to the Chinese entity 沧州句号网络科技有限公司 (Cangzhou Juhao Network Technology Co., Ltd.) has served as the operational backbone for at least 20 malicious Windows executables and DLLs spanning two distinct build waves — one in May 2025 and a second in September 2025 — all delivered through a Wangsu (ChinaNetCenter) CDN-fronted infrastructure that renders conventional IP-layer blocking effectively useless.
#SaltySpider#SoftCnApp#DeepData#code-signingabuse#CDNfronting#sandboxevasion#Chinese-languageWindowsusers#DLLsideloadingActorsSalty Spider · KuKuIOCf27 · i40 · d2 · u3
FILEMembersJun 9, 2026, 00:37 (UTC+9)Salty Spider Pairs 7-Year Loader With Fresh Phorpiex Worm to Hit Transport
##A Seven-Year Loader Meets a Zero-Day Worm: Salty Spider's Layered Evasion Campaign Targets Transportation A freshly compiled Phorpiex worm variant — PE timestamp matching its first submission date of 2026-02-09, zero prior detection history at the moment of deployment — is circulating alongside a seven-year-old MSIL/AgentB trojan that successfully convinces automated sandbox analysis it is harmless, even as 48 of 76 antivirus engines flag it as malicious. The pairing is not accidental.
#SaltySpider#Phorpiex#MSIL/AgentB#transportationsector#sandboxevasion#bulletproofhosting#USBsocialengineering#botnetC2ActorsSalty Spider · KuKuIOCf2 · i1 · d0 · u1MITRE25IndustriesTransportation
FILEMembersJun 9, 2026, 00:21 (UTC+9)Trojanized UltraSurf Proxy Rides Expired Cert Into 2026
A Win32 build of the UltraSurf/Ultrareach censorship-circumvention proxy — a tool millions have used to punch through national firewalls — is still circulating years after the code-signing certificate underpinning it expired. The leaf certificate, issued to "Ultrareach Internet Corp." and valid from June 9, 2021 to June 9, 2024, is now flagged by validators as "not time valid," yet the GlobalSign intermediate and root certificates above it in the chain remain valid through 2029 and 2030.
#UltraSurf#Ultrareach#Glupteba2#codesigningabuse#HurricaneElectricAS6939#self-signedcertificates#MuddyWater#SilentChollimaActorsMuddyWater · TEMP.ZagrosIOCf1 · i5 · d0 · u0MITRE18IndustriesEnergy
C&CMembersJun 8, 2026, 23:57 (UTC+9)Ludashi Adware Operator Pre-Positions Second DigiCert Certificate as Revocation Insurance
Eleven Windows PE files. Two distinct Chinese legal entities. A single DigiCert Trusted G4 code-signing root. And, as of this writing, every certificate still valid. The Ludashi adware campaign documented in earlier coverage has extended its operational footprint in ways that reveal deliberate, forward-looking infrastructure management rather than reactive patching.
#Ludashi#adware#code-signingabuse#certificaterotation#CDNinfrastructure#sandboxevasion#China#PolarWindActorsFIN6 · Skeleton SpiderIOCf31 · i60 · d0 · u1MITRE5
APTMembersJun 8, 2026, 23:36 (UTC+9)Signed FileZilla Installer Hides Adware Bundler Behind Valid Sectigo Chain
A file calling itself FileZilla_3.69.5_win32-setup.exe is circulating with a complete, currently-valid Sectigo code-signing chain — Tim Kosse through Sectigo Public Code Signing CA R36, Sectigo Public Code Signing Root R46, and the Sectigo (AAA) root — even as 12 of 75 antivirus engines classify it as adware.bundler/filezilla.
#FileZilla#adwarebundler#code-signingabuse#Sectigocertificate#NSISinstaller#APT28#APT15#threatintelmisattributionActorsAPT28 · StrontiumIOCf1 · i4 · d1 · u1MITRE9IndustriesEducation & Research
APTMembersJun 8, 2026, 23:07 (UTC+9)Lazarus Group Hides LummaC2 Stealer Behind Signed Installer and AWS CDN
Four indicators. Two signed Windows executables. Two AWS CloudFront subdomains that score zero detections across 91 engines. In practice, a delivery architecture that defeats network-layer blocking, suppresses antivirus verdicts on the second-stage payload to 4 out of 77 engines, and defeats dynamic analysis entirely — all simultaneously, all through infrastructure that any enterprise legitimately uses every day.
#LazarusGroup#LummaC2#code-signingabuse#AWSCloudFront#sandboxevasion#financialservices#trojanizedinstaller#informationstealerActorsLazarus Group · Hastati GroupIOCf2 · i0 · d2 · u0MITRE21RegionsAE · BR · FR · LYIndustriesFinancial Services
FILEMembersJun 8, 2026, 19:41 (UTC+9)PayPal Lure Fronts Three-Family Malware Stack Tied to FortiGate C2
A trojanised credential-checker masquerading as a PayPal email validation tool has been serving as the entry point for a multi-stage payload operation that deploys at least three functionally distinct malware families — all wrapped in the same ConfuserEx Mod obfuscation layer — before routing command-and-control traffic to a single Russian IP address that presents a FortiGate appliance certificate.
#Amadey#Mofksys#ConfuserEx#reflectiveloader#credentialtheft#Russia#paymentplatforms#wormIOCf12 · i1 · d0 · u3MITRE36RegionsRO
FILEMembersJun 8, 2026, 15:58 (UTC+9)Decade-Old Bundler Trojan Drops Tor-Routed MinerGate on Chemicals Workstations
A 919-kilobyte UPX-compressed Windows executable masquerading as a routine software installer is functioning as the first stage of a two-component cryptomining chain that has been circulating since at least late 2016 and remains actively observed as of mid-2026. The dropper — internally branded "Carambis Installer" and carrying a ROSTPAY LTD.
#PinchySpider#MinerGate#Carambisbundler#cryptomining#chemicalssector#TorC2#Proton66OOO#UPXpackingActorsPinchy Spider · SodinokibiIOCf3 · i6 · d0 · u0IndustriesChemicals
C&CMembersJun 8, 2026, 15:26 (UTC+9)EV Certificate Issued to ORYON TECH LIMITED Signs Four Malicious Payloads in Single Batch
At 8:36 on the morning of 23 April 2026, an operator pressed the metaphorical button on a code-signing ceremony that bound four distinct malicious payloads to a single Extended Validation certificate — a credential class that Sectigo's issuance process requires to be anchored to a verified legal entity. The entity named on that certificate is ORYON TECH LIMITED.
#ORYONTECHLIMITED#Microleaves#Jatif#Legion#EVcertificateabuse#adware#Argentina#IndiaIOCf21 · i1 · d5 · u6MITRE13RegionsAR · IN
APTMembersJun 8, 2026, 15:09 (UTC+9)Salty Spider Abuses Live DigiCert Cert for 17 Months of Malicious Builds
Seven Windows executables and DLLs flagged as adware — spanning two distinct 2345 Software product lines — carry an identical, currently-valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd., and the operator was still applying that same credential to fresh malicious builds as recently as April 7, 2026.
#SaltySpider#2345Software#code-signingabuse#adware#AlibabaCDN#China#T1553.002#softwaresupplychainActorsSalty Spider · KuKuIOCf15 · i16 · d2 · u2MITRE16
C&CMembersJun 8, 2026, 07:30 (UTC+9)Ludashi Campaign Adds Second Code-Signing Cert to Survive Revocation
##A Second Certificate, A Second Company: How the Ludashi Campaign Hardened Its Signing Infrastructure Since CTX Team's earlier coverage of the Ludashi adware and trojan campaign, twelve new file indicators, seven new IP addresses, and a new payload-delivery URL have surfaced — but the most operationally significant development is not the volume expansion.
#Ludashi#FIN6#code-signingabuse#adware#trojan#ChinaMobileAS9808#CDNfronting#DigiCertActorsFIN6 · Skeleton SpiderIOCf42 · i7 · d1 · u2MITRE13
C&CMembersJun 8, 2026, 07:18 (UTC+9)WoodyRAT Stealer Harvests Complete Exodus Wallet Secrets Across AS214351
Thirty-five new file indicators have joined the WoodyRAT-tagged campaign CTX Team first documented in earlier coverage, and almost none of them are malware. They are the stolen goods themselves — wallet seeds, two-factor secrets, session tokens, FTP credential stores, and instant-messenger account files pulled from victim machines and packaged into structured log bundles before being uploaded to a PHP panel sitting on a German IP address inside a single autonomous system registered less than…
#WoodyRAT#infostealer#Exoduswallet#Telegramsessiontheft#AS214351#cryptocurrencytheft#AlgeriaEthiopiaIndia#credentialharvestingIOCf52 · i3 · d0 · u5MITRE57RegionsDZ · ET · IN
APTMembersJun 7, 2026, 23:21 (UTC+9)DarkHotel's Decade-Old Nemim Trojan Still Evades Detection in 2026
A 56-kilobyte Windows executable first submitted to VirusTotal in February 2013 is still being resubmitted and tracked as an active threat as recently as March 2025 — and the infrastructure supporting it has grown fresher, not older. The implant at the centre of this campaign is Nemim, a multi-role trojan attributed by CTX Team to DarkHotel and directed at espionage targets in India.
#DarkHotel#Nemim#dynamic-DNS#India#espionage#sandboxevasion#commandandcontrol#APTActorsDarkHotel · Fallout TeamIOCf2 · i1 · d0 · u9MITRE28RegionsIN
APTMembersJun 7, 2026, 23:07 (UTC+9)BlueBottle's FileZilla Impersonation Campaign Hides XMRig Behind Zero-Detection ZIP
A PE32 dropper bearing a self-signed "FileZilla FTP Client" code-signing certificate — its validity start date of 2025-12-24 matching, to the day, the registration date of the campaign's C2 domain filezilla.cc — sits at the centre of a multi-stage XMRig cryptominer delivery chain that CTX Team has tracked from January through June 2026.
#BlueBottle#Opera1er#XMRig#cryptominer#DemocraticRepublicofCongo#code-signingabuse#encrypteddeliverycontainer#CloudflarefrontingActorsBlueBottle · Opera1erIOCf19 · i1 · d1 · u2MITRE29RegionsCD
C&CMembersJun 7, 2026, 20:10 (UTC+9)18 C2 Nodes Hide Behind Alibaba, Baidu, and 2345.com TLS Certs
Eighteen IP addresses flagged as command-and-control servers share an architectural feature that sets this campaign apart from conventional attacker-controlled hosting: every node in the set presents a TLS certificate belonging to a major Chinese internet platform — Alibaba CDN, Baidu, 2345.com, or Baidu DNS — making outbound C2 traffic structurally indistinguishable from routine HTTPS connections to some of China's highest-volume services.
#C2infrastructure#TLScertificateabuse#ChineseCDNblending#Chromeextensionmalware#sandboxevasion#ChinaUnicomAS4837#sslTrusCA#networkdetectionevasionIOCf50 · i18 · d0 · u0MITRE29