CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • C&CMembersJun 7, 2026, 19:58 (UTC+9)

    Signed Adware Toolkit Targets Telecom With Two Live DigiCert Certs

    Seventeen Windows executables and DLLs — spanning crash reporters, plugin managers, system tray utilities, and at least one component that a sandbox flagged as a remote-access trojan — are circulating under currently valid DigiCert Trusted G4 code-signing certificates issued to two Chinese corporate entities, with both certificates remaining valid until 2027.

    #Ludashi#PubNubRAT#code-signingabuse#adware#sandboxevasion#telecommunications#DLLsideloading#China
    ActorsFIN6 · Skeleton SpiderIOCf40 · i5 · d12 · u33MITRE20IndustriesTelecommunications
  • C&CMembersJun 7, 2026, 19:39 (UTC+9)

    Gaming-Cheat Lure Hides Kernel-Level LummaStealer Campaign

    A trojanized HWID-spoofer toolkit — distributed under gaming-cheat branding from at least three operator-controlled download endpoints — is delivering LummaStealer alongside a purpose-built kernel evasion stack that combines an expired EV-signed vulnerable driver with a test-certificate-signed spoofer component. The campaign's most recently observed artifact, a browser-store harvest file first seen on 2026-06-06, confirms active credential collection was underway within hours of CTX Team's…

    #LummaStealer#BYOVD#WinDivert#kernelevasion#gamingcommunitytargeting#credentialtheft#HWIDspoofer#APT28unconfirmed
    ActorsAPT28 · StrontiumIOCf17 · i5 · d3 · u6MITRE24
  • C&CMembersJun 7, 2026, 07:53 (UTC+9)

    CDN-Masquerade TLS Cluster and First C2 Domain Expand PubNubRAT Campaign

    Thirteen IP addresses spanning six Chinese autonomous systems — China Unicom, China Telecom, China Mobile, and Jinhua Weian InfoTech among them — have been found presenting an identical Sectigo DV wildcard certificate for *.bytecdn.cn (serial 152bfd07c372d944c3ac6feff2e606bd), forming a geographically distributed reverse-proxy layer that cloaks command-and-control traffic behind the TLS identity of one of China's largest consumer internet CDN brands.

    #PubNubRAT#TLSmasquerade#C2infrastructure#codesigningabuse#China#PUA#reverseproxy#CDNimpersonation
    ActorsFIN6 · Skeleton SpiderIOCf73 · i77 · d1 · u2MITRE10
  • APTMembersJun 7, 2026, 07:20 (UTC+9)

    Fake Synaptics Driver Rebuilt for Three Years, Now a Confirmed RAT

    Three unsigned Win32 loaders — the oldest first appearing in December 2020, the newest surfacing in November 2023 — share one imphash, an identical PE section layout down to the byte, and a forged compile timestamp of 1992-06-19 that predates Windows 95. All three carry the same fake product string, "Synaptics Pointing Device Driver," version 1.0.0.4, and two of them drop to the identical path, C:\ProgramData\Synaptics\Synaptics.exe.

    #Synapticsdrivermasquerade#DarkKomet#XRed#XWorm#imphashreuse#certificatefronting#dynamicDNSabuse#IndraPredatorySparrow
    ActorsIndra · Predatory SparrowIOCf13 · i5 · d0 · u0RegionsEC
  • C&CMembersJun 7, 2026, 03:54 (UTC+9)

    APT27 Toolkit Ties Six Malware Families to One C2 Cluster

    Nine Windows executables submitted to VirusTotal across a five-day window in late May and early June 2026 do not look, at first glance, like a coordinated campaign. The threat labels scatter across the taxonomy — a banker trojan here, a clipboard hijacker there, an EDR-bypass pair, a StealC loader, an Amadey dropper. The file sizes range from 42 KB to 868 KB. No shared code-signing certificate ties them together.

    #APT27#StealCv2#Amadey#ClipBanker#reflectiveloading#EDRbypass#Algeria#bulletproofhosting
    ActorsAPT27 · TEMP.HippoIOCf64 · i3 · d0 · u7RegionsDZ
  • C&CMembersJun 7, 2026, 03:39 (UTC+9)

    TA505 Hides Malware Behind 13-Year-Old Revoked Valve Certificate

    A SilverFox dropper circulating since early June 2026 carries a Valve Corporation code-signing certificate that expired in November 2012 and has been explicitly revoked — yet its PE timestamp reads 2025-08-18, a 13-year anachronism that is the clearest single indicator of deliberate stolen-cert abuse in this campaign. That certificate is only the first layer of a defense-evasion stack that also includes a Bring Your Own Vulnerable Driver (BYOVD) technique using a legitimately signed WinDivert…

    #TA505#LummaStealer#SalatStealer#Amadey#BYOVD#certificateabuse#gamingcommunitytargeting#Turkey
    ActorsTA505 · Hive0065IOCf16 · i5 · d2 · u7MITRE27
  • C&CMembersJun 6, 2026, 23:59 (UTC+9)

    One DigiCert Certificate, 17 Malicious Payloads, Three-Year Signing Window

    In September 2024, someone registered a code-signing certificate with DigiCert under the name of a Beijing technology company — 北京创想界科技有限公司 — and within six weeks began using it to sign malicious software. By the time CTX Team catalogued the full file cohort, that single certificate, serial number 06 FE 57 2B A6 2E 8E C3 18 03 0F DC 9B AC A2 81, had been applied to 17 distinct PE32 executables and DLLs spanning two trojanized utility brands, a modular plugin architecture, and at least one…

    #PubNubRAT#Ludashi#PolarWind#code-signingabuse#Chinesethreatactor#CDNinfrastructure#sandboxevasion#adwaredual-use
    ActorsAPT28 · StrontiumIOCf42 · i65 · d0 · u0MITRE26
  • APTMembersJun 6, 2026, 23:10 (UTC+9)

    Ludashi Adware Ring Abused DigiCert Certs Across Five Shell Firms

    Fifteen signed Windows executables. Five distinct Chinese company identities. One commercial certificate authority. A single cert serial binding nine of those payloads to a three-year production window that is still running. The operation CTX Team has been tracking targets the telecom sector and exploits a structural weakness that most enterprise endpoint stacks have not solved: when a binary carries a valid, trusted code-signing certificate, a significant fraction of the detection stack simply…

    #Ludashi#DigiCertcertificateabuse#code-signingevasion#adware#TencentCloudinfrastructure#telecommunicationssector#overlayhashmutation#certificaterevocationfailure
    ActorsGorgon Group · SubaatIOCf29 · i22 · d4 · u0MITRE10IndustriesTelecommunications
  • APTMembersJun 6, 2026, 19:24 (UTC+9)

    Expired and Revoked Certs Anchor Active Malware Delivery Chain

    Three Windows executables are circulating through software download channels carrying code-signing certificates that, by any standard enforcement logic, should stop them cold. One bears a DigiCert leaf certificate for an entity called VOICEFIVE, INC that expired on 3 April 2026. The other carries a Certum Extended Validation certificate for "AN Soft" that has been explicitly revoked.

    #APT28#surtr#certificateabuse#code-signing#PremierOpinion#sandboxevasion#technologysector#supplychaindelivery
    ActorsAPT28 · StrontiumIOCf4 · i5 · d5 · u0MITRE7IndustriesTechnology
  • FILEPublicJun 6, 2026, 16:11 (UTC+9)

    Trojanised KMS Activators Carry Konni Espionage Implant, WinDivert Sniffer

    Five trojanised Windows activation tools — distributed under the names KMSpico, KMSAuto, and AAct — carry an embedded user-mode packet-capture driver that has no legitimate place in any licensing utility. The YARA rule WinDivert_Driver fires on all five samples, and on one of them, AAct_x64.exe (sha256: db3aa782e297b2b5d9e2a1281ebb9afd416c82722c2d2a285ef94070e4cdd5d2), a second rule fires alongside it: win_konni_auto, a Malpedia-sourced signature that detects the Konni espionage implant family.

    #GamaredonGroup#Konni#WinDivert#KMSpico#piracylure#defencesector#code-signingabuse#espionage
    ActorsGamaredon Group · CTIGIOCf7 · i0 · d0 · u0MITRE6IndustriesDefense
  • FILEPublicJun 6, 2026, 16:00 (UTC+9)

    Trojanized Macro Tool Drops BroPass and RedlineStealer on Chilean Targets

    A 32-kilobyte Windows executable masquerading as a macro encryption utility has become the delivery vehicle for one of the more technically deliberate credential-theft operations CTX Team has tracked against Chilean targets in recent memory. The outer wrapper — an NSIS installer named macro_encrypter.exe — drops at least two distinct stealer families onto victim machines while simultaneously executing a layered evasion stack that includes active sandbox detection, base64-encoded gzip payloads,…

    #OperationSpalax#BroPass#RedlineStealer#NSISdropper#credentialtheft#Chile#sandboxevasion#code-signingabuse
    ActorsOperation SpalaxIOCf3 · i0 · d0 · u1MITRE30RegionsCL
  • C&CMembersJun 6, 2026, 15:47 (UTC+9)

    Salty Spider Adds Second CDN Channel to Trojanized 2345PCSafe Delivery

    Since CTX Team's earlier coverage of this campaign, the delivery infrastructure backing the trojanized 2345PCSafe (2345安全卫士) security suite has grown in a specific and operationally significant direction: a second CDN-fronted update endpoint, dl-up.2345cdn.com, is now confirmed active alongside the previously documented download.2345cdn.com, and 23 additional IP addresses have been mapped to the anycast pools behind both domains.

    #SaltySpider#2345PCSafe#ad2345#chinad#supplychaincompromise#CDNabuse#codesigningabuse#mainlandChina
    ActorsSalty Spider · KuKuIOCf59 · i25 · d2 · u2MITRE2
  • C&CMembersJun 6, 2026, 11:58 (UTC+9)

    Three Certs, One Chain: Signed Adware Campaign Evades Revocation for 8 Months

    Seventeen signed Windows executables, three DigiCert code-signing certificates, three distinct Chinese corporate identities, and an eight-month continuous production window: what CTX Team has catalogued in this campaign is not a single malicious installer but an industrialised signing infrastructure engineered to survive the most common defensive response to signed malware — certificate revocation.

    #TA551#Ludashi#Chinad#code-signingabuse#certificaterotation#sandboxevasion#China-nexus#adware-trojan
    ActorsTA551 · ShathakIOCf35 · i18 · d3 · u0MITRE3
  • C&CMembersJun 6, 2026, 11:40 (UTC+9)

    APT28 Hides PBot Stealer Inside Validly Signed Bright Data SDK Binary

    A 12-megabyte Windows executable carrying a fully valid DigiCert code-signing certificate for "Bright Data Ltd" — a commercially distributed proxy and VPN software vendor — is circulating as the stealth layer of an espionage toolkit that CTX Team has attributed to APT28, the Russian state-aligned threat group also tracked under aliases including Fancy Bear, Forest Blizzard, and Sofacy.

    #APT28#PBotstealer#BrightDataSDKabuse#code-signingchainexploitation#KMSactivationlure#C2certificaterotation#Dotfuscatorpacking#Cloudflareproxying
    ActorsAPT28 · StrontiumIOCf4 · i2 · d7 · u1MITRE11
  • APTMembersJun 6, 2026, 11:07 (UTC+9)

    Three Shell Companies, One Pipeline: Chinese Signing Op Delivers PubNubRAT

    Sixteen malicious Windows executables and DLLs are currently circulating under valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 certificates — each certificate issued to a distinct Chinese-registered legal entity, each carrying a three-year validity window, and each actively suppressing the dynamic analysis environments that defenders rely on to catch what static signatures miss. The operation is not a single rogue certificate.

    #PubNubRAT#Ludashi#Chinad#code-signingabuse#China-nexus#DigiCert#AS4837#supplychaindelivery
    ActorsFIN6 · Skeleton SpiderIOCf40 · i5 · d3 · u1MITRE18
  • FILEMembersJun 6, 2026, 07:45 (UTC+9)

    72-Hour Microsoft Cert Turns Warp Terminal Installer Into Signed Dropper

    On the morning of June 5, 2026, a trojanised installer impersonating the Warp Terminal application appeared on VirusTotal carrying a code-signing certificate that had been minted fewer than 48 hours earlier. The leaf cert — serial 33 00 01 A1 1D A4 AE AD B1 B2 1A 0F 7C 00 00 00 01 A1 1D, issued by Microsoft ID Verified CS EOC CA 04 under the subscriber identity "Denver Technologies, Inc. dba Warp" — was valid for exactly 72 hours, from June 3 to June 6, 2026.

    #ephemeralcodesigning#MicrosoftTrustedSigning#ProcessHacker2#trojanisedinstaller#signedbinaryabuse#TorC2#commercialservices#supplychaindelivery
    ActorsRoyal Ransomware · Team OneIOCf8 · i0 · d0 · u0MITRE6IndustriesCommercial Services
  • C&CMembersJun 6, 2026, 07:32 (UTC+9)

    Five-Family Infostealer Campaign Bypasses Chrome 127 Encryption via Single Rogue AS

    A multi-stage infostealer and clipboard-hijacking campaign deploying at least five distinct malware families — Amadey, StealC v2, two statically linked ClipBanker variants, and a purpose-built custom dropper — has been routing all of its command-and-control traffic exclusively through AS214351, a single autonomous system operated by Femo It Solutions Limited that was created in October 2024 and spans address space registered under two separate regional internet registries.

    #Amadey#StealCv2#ClipBanker#AS214351#Chromiumapp-boundencryptionbypass#clipboardhijacking#crimewareinfrastructure#Brazil
    IOCf43 · i3 · d0 · u7RegionsBR
  • C&CMembersJun 6, 2026, 03:38 (UTC+9)

    Three Chinese Firms Rotate DigiCert Certs to Keep Adware Trusted

    Twenty Windows executables and DLLs — every single one carrying a valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 signature — are circulating under the guise of security and system-optimisation software, with the signing authority rotating across three distinct Chinese corporate entities to sustain a trusted posture as individual certificates accumulate antivirus detections.

    #Ludashi#Polarwind#DigiCertcertificateabuse#code-signingrotation#adware-trojan#China#CDNinfrastructureevasion#SaltySpider
    ActorsTA551 · ShathakIOCf58 · i72 · d3 · u3MITRE8
  • APTMembersJun 6, 2026, 03:06 (UTC+9)

    Expired C2 Domain Closes Loop on Red Apollo KMSPico Adware Campaign

    A single domain registered in October 2017 — idyllicdownload.com, acquired through Silver Domain Names LLC and abandoned within a year — has emerged as the confirmed network checkin endpoint for a pair of NSIS-packaged OutBrowse adware installers that masquerade as the KMSPico Windows activation crack. The domain's addition to the indicator catalog closes the delivery-to-C2 loop on a campaign attributed to Red Apollo, the China-aligned threat actor also tracked under the aliases APT10,…

    #RedApollo#APT10#OutBrowse#NSISinstaller#KMSPicolure#Germanmanufacturing#C2infrastructure#adwarecampaign
    ActorsRed Apollo · PotassiumIOCf6 · i0 · d1 · u2MITRE38RegionsDEIndustriesManufacturing
  • C&CMembersJun 6, 2026, 00:07 (UTC+9)

    One DigiCert Certificate Binds 18 Malicious Ludashi Components Through 2027

    Eighteen Windows PE files — a mix of executables and DLLs spanning a full PC utility lifecycle, from disk defragmentation to a lockscreen manager to an uninstaller — are circulating under the Ludashi (鲁大师) software brand, every one of them bearing an identical, currently-valid DigiCert Trusted G4 code-signing certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co. Ltd.).

    #ChengduQiluTechnology#Ludashi#Chinad#adware#code-signingabuse#fast-fluxDNS#TLSimpersonation#China
    IOCf66 · i5 · d2 · u4MITRE19
  • APTMembersJun 5, 2026, 23:19 (UTC+9)

    Fake ChatGPT Installer Hides Proxy SDK Classified as PBot Stealer

    When a user downloads what appears to be a Windows client for ChatGPT from chatgpt-windows.top — a domain registered on 2025-06-03 and already flagging 13 of 91 engines on VirusTotal — they receive something considerably more complex than a VPN application. CTX Team's analysis of this campaign reveals a layered abuse chain in which trojanized VPN installers branded as WireVPN and VPNMaster silently co-install a Dotfuscator-obfuscated .NET component signed by Bright Data Ltd that two independent…

    #PBotstealer#WireVPN#VPNMaster#BrightDataSDK#expiredEVcertificates#residentialproxyabuse#softwarebundlingsupplychain#AI-lurephishing
    ActorsSpace Pirates · WebwormIOCf51 · i33 · d76 · u14MITRE20
  • FILEPublicJun 5, 2026, 12:39 (UTC+9)

    Emotet C2 Uses Auto-Rotating Certs and Zero-Detection Japan Node

    A 143-kilobyte Word document disguised as a Windows system file sits at the entry point of a campaign targeting Canadian telecommunications organisations — but the more operationally significant story lies in what happens after that document executes. The command-and-control infrastructure behind this Emotet-attributed operation combines automated 89-day Let's Encrypt wildcard certificate rotation across operator-controlled domains with a fully undetected hosting node on SAKURA Internet's…

    #Emotet#TA542#C2infrastructure#Let'sEncryptcertificateabuse#Canadiantelecommunications#SAKURAInternet#WordPresspathmimicry#phishingdocument
    ActorsEmotet Group · TA542IOCf3 · i1 · d2 · u3RegionsCAIndustriesTelecommunications
  • FILEMembersJun 5, 2026, 08:40 (UTC+9)

    XWorm RAT Campaign Stacks Four Evasion Layers Across 57 Countries

    A ZIP archive disguised as a routine purchase-order document is the entry point for one of the more methodically constructed XWorm RAT delivery chains CTX Team has documented in recent months. The campaign — active since at least mid-May 2026 and reaching victims across 57 countries and 15 industry verticals — does not rely on any single clever trick.

    #XWorm#RAT#purchaseorderlure#compile-after-delivery#sandboxevasion#LatinAmerica#financialservices#manufacturing
    IOCf11 · i1 · d1 · u3MITRE50RegionsAE · AT · AU · BDIndustriesArts & Entertainment · Automotive · Construction
  • C&CMembersJun 5, 2026, 08:24 (UTC+9)

    Signed-Adware Campaign Adds PubNubRAT and New C2 Backend

    Since CTX Team's earlier coverage of this campaign's UnionPay-fingerprinted TLS infrastructure, the operation has expanded in two structurally significant directions: a wholly new, function-partitioned command-and-control backend has been provisioned under the domain tjbxldkj.cn, and eight fresh IP addresses bound by a shared Sectigo wildcard certificate have joined the delivery layer — all absent from the prior reporting.

    #PubNubRAT#code-signingabuse#China-nexusthreatactor#cloudC2evasion#PCoptimizermalware#DigiCertcertificatemisuse#CDNdeliveryinfrastructure#sandboxevasion
    IOCf31 · i8 · d4 · u3MITRE23
  • C&CMembersJun 5, 2026, 08:07 (UTC+9)

    Stealc v2 Chromium Bypass Moves to Active Campaign in Vietnam

    Three Windows executables circulating in a Vietnam-region campaign have been confirmed by sandbox analysis and six independent YARA rules as carrying Stealc v2's built-in bypass for Chromium app-bound encryption — a credential-protection mechanism Google introduced in 2024 specifically to block the kind of browser-password extraction that infostealer markets had relied on for years.

    #Stealcv2#Amadey#clipboardhijacker#Chromiumapp-boundencryptionbypass#Vietnam#AS214351#credentialtheft#cryptocurrencytheft
    IOCf20 · i3 · d9 · u4MITRE31RegionsVN
  • APTMembersJun 5, 2026, 07:37 (UTC+9)

    Three Chinese Shell Firms, One DigiCert Chain, and a Kernel Driver in an Adware Campaign

    Fourteen months of continuous payload production. Eleven distinct PE files — DLLs and installer EXEs alike — all bearing the same unrevoked leaf certificate issued to a single Beijing-registered technology company. A second Chinese entity in Chengdu holding its own valid DigiCert credential, and a third Chengdu firm with a third.

    #SaltySpider#BYOVD#WinRing0#code-signingabuse#PUAadware#China#DigiCertcertificatechain#CDNfronting
    ActorsSalty Spider · KuKuIOCf37 · i12 · d3 · u3MITRE32
  • C&CMembersJun 4, 2026, 23:51 (UTC+9)

    Phorpiex Botnet Runs Six-Path C2 Panel With Tor Fallback to Target Mexico

    A single IP address geolocated to the Seychelles is currently serving six sequentially numbered HTTPendpoints — /cc11, /cc22, /cc33, /cc44, /cc55, and /cc66 — alongside a Tor hidden-service fallback, forming the operational backbone of an active Phorpiex botnet campaign targeting Mexico. CTX Team first observed this infrastructure on 4 June 2026.

    #Phorpiex#botnet#C2infrastructure#sandboxevasion#Torhiddenservice#Mexico#ransomware#time-basedevasion
    IOCf3 · i3 · d1 · u7MITRE36RegionsMX
  • C&CMembersJun 4, 2026, 23:40 (UTC+9)

    Ludashi Campaign Staged Eight C2 Subdomains Four Months Before First Payload

    Since CTX Team's earlier coverage established the signed-binary tradecraft at the core of this operation, the picture of how those payloads reach victims has come into focus. The new signal is entirely network-side: eight xhyktech.com subdomains provisioned in a single registration batch on 2025-03-10, three of them now unified under a wildcard TLS certificate issued by the Chinese CA iTrust, Inc.

    #Ludashi#ZXStoreX#xhyktech.com#adware#CDNfronting#codesigningabuse#Chinesethreatinfrastructure#pluginloader
    IOCf13 · i3 · d8 · u9MITRE43
  • APTMembersJun 4, 2026, 23:26 (UTC+9)

    CapableWin Adware Suite Signed in Nine Minutes, Certificate Still Live

    Seven Windows executables branded as "CapableWin" — a Chinese-language PC utility marketed as 全能电脑助手, or "All-in-One PC Assistant" — were compiled, versioned, and signed within a nine-minute window on the morning of 8 September 2025, all carrying a currently-valid GlobalSign code-signing certificate issued to Beijing entity 北京华网智讯软件有限公司 that remains unrevoked despite detection rates reaching 39 of 77 engines across the suite.

    #MustangPanda#SoftCnApp#IcedID#code-signingabuse#CDNtrafficblending#Chineseadwareecosystem#PEoverlayconcealment#Windowsendpoint
    ActorsMustang Panda · HoneyMyteIOCf7 · i27 · d0 · u0
  • APTMembersJun 4, 2026, 23:13 (UTC+9)

    19 Trojanized IME Files Share One DigiCert Cert, Route C2 Through China's Largest CDN

    ##One Certificate, Nineteen Payloads: How a Wubi IME Trojan Hides Behind a Valid DigiCert Signature and China's Largest CDN Nineteen Windows executables — all masquerading as the 万能五笔输入法 (WanNeng Wubi IME) Chinese input-method suite and all carrying a single valid DigiCert code-signing certificate issued to Shanghai Oriental Webcasting Co. Ltd.

    #SaltySpider#SoftCNApp#Burden#Fragtor#code-signingabuse#CDNinfrastructureblending#ChineseIMEmasquerade#ICMPreconnaissance
    ActorsSalty Spider · KuKuIOCf23 · i10 · d0 · u0MITRE10
  • APTMembersJun 4, 2026, 19:21 (UTC+9)

    APT28 Hides RAT Stack Inside Trojanised Deepfake AI Tool

    A 43-megabyte Windows executable named Deep-Live-Cam-VFX.exe — convincingly dressed as a popular open-source deepfake application — has been circulating across at least nine independent submission sources, carrying inside it a PyInstaller-packed payload cluster that drops VenomRAT, a clipboard hijacker, and a browser credential stealer onto victim machines.

    #APT28#VenomRAT#njRAT#LummaStealer#deepfakelure#VietnamC2infrastructure#credentialharvesting#cryptocurrencywallettheft
    ActorsAPT28 · StrontiumIOCf9 · i0 · d3 · u3MITRE53RegionsNL · TR
  • C&CMembersJun 4, 2026, 11:37 (UTC+9)

    Shell Companies, Signed Malware, and a RAT Hidden in a PC Cleaner

    Seventeen Windows binaries circulating across Chinese consumer software ecosystems carry valid DigiCert Trusted G4 Code Signing certificates — but the two Chengdu-registered entities that obtained those certificates appear to exist solely to launder signing trust onto malicious code. The scheme is not a one-off: CTX Team's analysis documents a deliberate rotation cycle spanning more than two years, with one entity procuring a replacement certificate within the same month its predecessor expired…

    #PubNubRAT#code-signingabuse#Ludashiecosystem#shellcompanyinfrastructure#ChinaUnicombackbone#certificaterotation#supply-chaindelivery#sandboxevasion
    IOCf39 · i16 · d0 · u0MITRE17
  • FILEPublicJun 4, 2026, 07:55 (UTC+9)

    Gorgon Group's Remcos Campaign Hides Behind Three Evasion Layers and a Swiss No-Log VPN

    A 131-kilobyte ZIP archive named "STATEMENT OF ACCOUNT - JULY'24.zip" is the entry point for a Remcos RAT campaign that layers three distinct anti-analysis mechanisms into its payload before beaconing to a Swiss no-log VPN node — a C2 address that was still receiving fresh TLS certificates as recently as May 2026, roughly six years after the initial payload cluster first appeared on VirusTotal.

    #GorgonGroup#RemcosRAT#SmartAssemblyobfuscation#sandboxevasion#phishing#no-logVPNinfrastructure#financiallure#PEiDpacking
    ActorsGorgon Group · SubaatIOCf6 · i1 · d0 · u1MITRE46
  • C&CMembersJun 4, 2026, 07:38 (UTC+9)

    Sality Botnet Still Active After 15 Years, Adds Zero-Detection Payload

    Fourteen distinct HTTP beacon paths. Two C2 domains. A core sample that has been resubmitted to threat intelligence platforms continuously from July 2010 through October 2025. And, sitting at the edge of this campaign, a file submitted just days before this analysis — typed as JSON, carrying zero detections across 76 engines, with an alternate name pointing to a randomised executable path buried deep inside Program Files. The Sality polymorphic file-infector is not a relic.

    #SaltySpider#Sality#Expiro#Tofsee#polymorphicfile-infector#USBautorun#Cameroon#C2infrastructure
    ActorsSalty Spider · KuKuIOCf31 · i1 · d5 · u17RegionsCM
  • APTMembersJun 4, 2026, 07:09 (UTC+9)

    17-Year-Old Kernel Driver Powers 2026 Espionage Campaign Across Five Nations

    A cryptominer, a clipboard hijacker, a reflective-loading stealer, and a Bring-Your-Own-Vulnerable-Driver instrument built from a kernel module first compiled in 2008 — this is the toolkit CTX Team has been tracking across targets in Brazil, India, Lithuania, Mexico, and Romania since late April 2026. The campaign's most operationally distinctive feature is not any single payload but the deliberate pairing of freshly compiled 2026-era commodity stealers with WinRing0x64.sys (sha256:…

    #BYOVD#WinRing0x64#Vidarstealer#Salatstealer#clipboardhijacker#cryptominer#Lithuania#AezaGroupAS210644
    ActorsAPT28 · StrontiumIOCf22 · i2 · d0 · u4MITRE61RegionsBR · IN · LT · MX
  • C&CMembersJun 3, 2026, 23:52 (UTC+9)

    Stealc v2, ClipBanker, AgentB Hit Crypto Wallets via Single Rogue ASN

    A financially motivated campaign active through May and June 2026 has deployed three functionally distinct malware families — Stealc v2, a ClipBanker, and an AgentB-family trojan — against the same command-and-control infrastructure, producing confirmed victim artefacts that include four encrypted Exodus cryptocurrency wallet files and a FileZilla FTP credential store.

    #Stealcv2#ClipBanker#AgentB#cryptocurrencytheft#AS214351#importtableobfuscation#Exoduswallet#infostealer
    IOCf30 · i2 · d0 · u5MITRE43RegionsRS
  • FILEMembersJun 3, 2026, 20:26 (UTC+9)

    Gaming-Cheat Lures Deploy XWorm RAT and Monero Miner in Europe

    ##Gaming-Cheat Lures Deliver XWorm RAT and Monero Miner to European Windows Users A campaign targeting Windows users in Germany and Poland is exploiting the appetite for gaming-cheat utilities to deliver a dual-payload combination of XWorm remote-access trojan and XMRig Monero miner — a financially motivated operation that layers sandbox evasion, debugger detection, and PE timestamp manipulation to reduce the likelihood of activation in analyst environments.

    #XWorm#XMRig#gaminglure#credentialtheft#cryptomining#Germany#Poland#sandboxevasion
    IOCf32 · i1 · d1 · u2MITRE17RegionsDE · PL
  • APTMembersJun 3, 2026, 19:10 (UTC+9)

    13 Trojanized Updates, Two Live Certs: Inside a Chinese CDN Signing Abuse Campaign

    Thirteen malicious Windows executables bearing valid, unrevoked Authenticode signatures from two separate Chinese software vendors have been circulating inside the update pipelines of widely-installed consumer applications — a signed-binary abuse chain [T1553.002] that walks past Authenticode-based endpoint defences on every build produced across a six-month window.

    #signedbinaryabuse#Authenticode#Chinadadware#Rhadamanthys#supplychaincompromise#Chineseconsumersoftware#CDNdelivery#Skip-2.0
    ActorsAPT28 · StrontiumIOCf28 · i26 · d2 · u6MITRE11
  • C&CMembersJun 3, 2026, 13:58 (UTC+9)

    1-of-76 Dropper Anchors Two-Year Microsoft Path Masquerade Campaign

    A freshly compiled Windows executable detected by exactly one of 76 antivirus engines sits at the entry point of a multi-layered implant campaign that has been quietly refreshing its toolset for the better part of two years. The file calls itself SecurityHealthServiceSyncUpdate.exe, drops under C:\Program Files\Microsoft\Servicing\, and carries a PE compile timestamp of 2026-05-13 — one day before it first appeared on VirusTotal.

    #SpringDragon#LotusBlossom#proxyware#trojanproxy#Microsoftpathmasquerade#Cloudflarefronting#APTespionage#Windowsimplant
    ActorsSpring Dragon · Lotus BlossomIOCf6 · i7 · d3 · u0MITRE9
  • APTMembersJun 3, 2026, 12:23 (UTC+9)

    APT29 Deploys Four-Layer Browser Fingerprinting in Energy-Sector Spearphish

    A spearphishing operation targeting energy-sector organisations has surfaced carrying an unusually disciplined anti-analysis architecture: two purpose-built domains deploying keyed URL access control, real-time browser fingerprinting via User-Agent Client Hints, per-victim randomized path generation, and a delivery-confirmation pixel beacon — four independent mechanisms operating in concert to profile victims, gate payload access, and frustrate automated detection, all before a single…

    #APT29#CozyBear#spearphishing#browserfingerprinting#User-AgentClientHints#energysector#keyedURLaccesscontrol#campaigninfrastructure
    ActorsAPT29 · MinidionisIOCf0 · i1 · d2 · u15MITRE4IndustriesEnergy
  • C&CMembersJun 3, 2026, 09:00 (UTC+9)

    TA505 Campaign Climbs Certificate Trust Ladder to Zero-Detection EV Binary

    A single campaign distributing trojanized KMS activators and download-manager reset tools has assembled one of the more deliberately layered code-signing abuse chains CTX Team has documented in recent months: an expired Sectigo leaf certificate that still evades roughly 38 antivirus engines, a currently valid DigiCert chain carrying a MediaGet PUA, and — at the top of the trust ladder — a valid Extended Validation certificate issued to DeepL SE under GlobalSign's GCC R45 hierarchy, producing a…

    #TA505#code-signingabuse#EVcertificate#KMSactivatorlure#ramnit#DLLsideloading#fast-fluxC2#credentialharvesting
    ActorsTA505 · Hive0065IOCf10 · i3 · d2 · u0MITRE29
  • C&CMembersJun 3, 2026, 08:25 (UTC+9)

    Expired 2022 EV Timestamp Lets LockBit's IP Scanner Slip Past 74 of 76 AV Engines

    A Varist-packed Windows executable weighing just over 20 megabytes is circulating via a spearphishing link at adbuho.shop/iqoja, presenting itself as the legitimate Famatech Corp. Advanced IP Scanner installer — and walking past 74 of 76 antivirus engines in the process. The secret to that near-total evasion is not a novel obfuscation technique or a freshly minted fraudulent certificate.

    #LockBitGang#AdvancedIPScanner#code-signingabuse#living-off-the-land#Authenticodetimestamp#spearphishing#C2infrastructure#MediaFireCDNabuse
    ActorsLockbit GangIOCf2 · i5 · d4 · u2MITRE4
  • C&CMembersJun 3, 2026, 04:26 (UTC+9)

    Fake Speed-Checker Masks a Decade-Long PUP Distribution Platform

    Sixteen HTTPS requests. Two path templates. One hardcoded affiliate token. The architecture behind a shlayer-family PUP operation targeting energy-sector endpoints turns out to be less a piece of malware and more a managed distribution platform — one whose C2 infrastructure has been actively maintained into 2026 despite payload files that first appeared on VirusTotal in the summer of 2015.

    #shlayer#PUPdistribution#C2infrastructure#affiliatetoken#self-signedcertificate#energysector#HTTPSmasquerade#update.buffernavpose.com
    IOCf2 · i0 · d1 · u16MITRE15IndustriesEnergy
  • APTMembersJun 3, 2026, 04:08 (UTC+9)

    Complete Mimikatz Toolkit Deployed in Telecom Credential Campaign

    A fully intact Mimikatz 2.2.0.0 distribution — kernel driver, main executable, credential-interception DLL, PrintNightmare exploit module, and distribution archive, all ten components present across both x64 and x86 architectures — has been deployed alongside Impacket ntlmrelayx Python relay scripts and cross-platform Chisel tunnel binaries in a campaign targeting the telecommunications sector.

    #Mimikatz#Impacketntlmrelayx#Chisel#PrintNightmare#NTLMrelay#credentialharvesting#telecommunications#ActiveDirectory
    ActorsSandworm · QuedaghIOCf22 · i0 · d0 · u0MITRE12IndustriesTelecommunications
  • APTMembersJun 2, 2026, 16:01 (UTC+9)

    Valid BitTorrent Certificate Smuggles Trojan Past Endpoint Defences

    A trojanised uTorrent Web installer bearing a currently-valid BitTorrent Inc code-signing certificate — serial 07 57 ED 74 D0 2A B0 00 FE AB 74 59 A3 34 CB 63, issued by DigiCert and valid through 2026-12-16 — is circulating as a dropper for a multi-stage payload chain that combines living-off-trusted-infrastructure staging, a repurposed censorship-circumvention tool, and a scripted certificate-rotation playbook on adjacent Hurricane Electric addresses.

    #code-signingabuse#UltraSurf#HurricaneElectric#NSISInetc#living-off-trusted-infrastructure#Tortunnelling#certificaterotation#trojandropper
    ActorsMuddyWater · TEMP.ZagrosIOCf4 · i3 · d0 · u0MITRE15
  • FILEPublicJun 2, 2026, 12:47 (UTC+9)

    Signed Netease Emulator Files Hide MSSQL Backdoor, Fool All 76 AV Engines

    Two trojanized components of Netease's MuMuPlayer Android emulator — both carrying a currently valid DigiCert code-signing certificate issued to Netease Interactive Entertainment Pte. Ltd. — have been identified embedding Skip-2.0 MSSQL authentication-bypass hooks inside legitimately signed Windows executables, achieving complete evasion across all 76 antivirus engines while routing command-and-control traffic through infrastructure that impersonates Akamai CDN.

    #SpringDragon#Skip-2.0#MuMuPlayer#code-signingabuse#MSSQLbackdoor#educationandresearchsector#Akamaiimpersonation#supplychaincompromise
    ActorsSpring Dragon · Lotus BlossomIOCf2 · i3 · d1 · u0IndustriesEducation & Research
  • C&CMembersJun 2, 2026, 08:31 (UTC+9)

    Prometei Botnet Runs Three Years on SSH Exploits, One C2 Still Live

    A 303-kilobyte Windows executable has been circulating since at least February 2023, quietly fetched by hosts compromised through internet-facing SSH and Telnet services, dropped into a Dell-branded subdirectory under a deliberately misspelled filename, and phoning home to a two-tier command-and-control architecture that spans a now-sinkholed domain and an active fast-flux node still live as of June 2026.

    #Prometei#OilRig#Cactusransomware#SSHexploitation#healthcare#telecommunications#botnet#command-and-controlinfrastructure
    ActorsOilRig · APT34IOCf2 · i1 · d2 · u2MITRE9IndustriesHealthcare · Telecommunications
  • C&CMembersJun 2, 2026, 08:17 (UTC+9)

    13-Node C2 Pool Borrows UnionPay Wildcard TLS to Mask Ludashi Adware

    Thirteen China-geolocated IP addresses, distributed across five distinct autonomous systems, are presenting a wildcard TLS certificate belonging to UnionPay International Co., Ltd. as their HTTPS identity — a trust-borrowing technique that gives campaign traffic the appearance of legitimate Chinese financial-sector communications.

    #Ludashiecosystem#UnionPaycertificateabuse#code-signingevasion#C2infrastructure#ChinaISP#adware#TLStrustabuse#DigiCert
    ActorsFIN6 · Skeleton SpiderIOCf58 · i14 · d1 · u0MITRE3IndustriesTelecommunications
  • FILEMembersJun 2, 2026, 02:27 (UTC+9)

    Kimsuky Hides Guloader Behind Fake 'Brittlewort' Code-Signing Identity

    A 326-kilobyte Windows executable named Zamówienie_Nr.2605011793800182.exe — Polish for "Order No." with a plausible invoice string appended — arrived in analysis pipelines on 18 May 2026 carrying a code-signing certificate issued by an entity called "Brittlewort." The name appears nowhere in any public certificate authority registry. It is self-issued, self-signed, and anchored to no trusted root.

    #Kimsuky#Guloader#code-signingabuse#spear-phishing#sandboxevasion#Poland#NSISdropper#PEtimestampforgery
    ActorsKimsuky · Velvet ChollimaIOCf9 · i0 · d0 · u0MITRE18RegionsAU · DE · PLIndustriesAgriculture · Arts & Entertainment · Commercial Services
  • FILEMembersJun 2, 2026, 02:13 (UTC+9)

    Two EV Certificates Power Dual-Brand VPN Malware Evading Sandboxes

    Seven Windows executables masquerading as legitimate VPN software — split across two distinct product families, WireVPN and VPNMaster — are circulating with valid Extended Validation code-signing certificates from two separate corporate entities, producing clean sandbox verdicts even as antivirus engines flag them at rates between 10 and 35 out of 76.

    #Barium#APT15#WireVPN#VPNMaster#EVcode-signingabuse#sandboxevasion#foodandbeveragessector#trojanisedVPNsoftware
    ActorsBarium · Wicked SpiderIOCf15 · i8 · d25 · u3MITRE20IndustriesFood & Beverages
7
Of10
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.