APTMembersMay 30, 2026, 10:44 (UTC+9)Chrome-Impersonating Mach-O Binaries Hit Government Macs With 0/76 AV Detections
Two universal Mach-O binaries impersonating Google Chrome — signed with a valid Apple Developer-issued certificate bearing the Google LLC identity, yet carrying a MissingPlist code-signing verdict that defeats Gatekeeper's full bundle validation — are circulating against government-sector macOS targets with zero detections across 76 antivirus engines.
#Cactus#MissingPlist#macOS#governmentsector#signedbinaryabuse#DNS-over-HTTPS#Chromeimpersonation#Mach-OActorsCactus · Cactus Ransomware GroupIOCf2 · i2 · d4 · u4MITRE5IndustriesGovernment
FILEMembersMay 30, 2026, 07:30 (UTC+9)Pay-Per-Install Campaign Adds CryptOne Dropper and Two C2 Domains in Nine Days
Since CTX Team's earlier coverage of this pay-per-install operation, the campaign has added ten new file indicators, stood up two freshly provisioned command-and-control domains within nine days of each other in May 2026, and introduced a raw-IP payload-delivery endpoint on a Netherlands-based host whose TLS certificate presents a deliberately misleading identity.
#pay-per-install#CryptOne#Microleavesadware#ORYONTECHLIMITED#OmegatechLTD#EVcertificateabuse#fakecrackedsoftware#NetherlandsC2infrastructureIOCf23 · i1 · d3 · u6MITRE31RegionsBR · EG · GB · PLIndustriesTechnology
C&CMembersMay 30, 2026, 07:04 (UTC+9)Trojanised VPN Installer Weaponises Two Legitimate Code-Signing Chains
A 14.5-megabyte NSIS self-extracting archive named WireVpn_v3.6.0.3-6872e76.exe has been circulating through a curated software-distribution channel labelled "TS Recommended Apps" — bearing a valid Extended Validation code-signing certificate from GlobalSign, issued to a Chinese-registered entity called WEILAI NETWORK TECHNOLOGY CO., LIMITED, and dropping kernel-level netfilter drivers alongside proxy and jumper binaries that collectively form an espionage-oriented command-and-control platform.
#WireVPN#PBot#WEILAINETWORKTECHNOLOGY#BrightDataSDK#code-signingabuse#netfilterkerneldriver#signedbinaryproxyexecution#credentialstealerActorsSprite Spider · Gold DupontIOCf27 · i27 · d94 · u12MITRE24
APTMembersMay 30, 2026, 06:22 (UTC+9)One Code-Signing Cert, 15 Malware Families, Valid Until 2027
A single DigiCert code-signing certificate issued to a Chinese commercial entity has been used to sign 15 distinct malicious PE32 executables spanning six threat families over a twelve-month window — and it remains valid through May 2027. The certificate, issued to 成都奇鲁科技有限公司 (serial 0D078E70EAEE48FFEB9576BDD400BE98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0), has functioned as a persistent OS-level trust bypass [T1553.002] across the entire payload portfolio, enabling malicious…
#SaltySpider#Ludashi#Chinad#Doina#code-signingabuse#ChinesePUAecosystem#signedbinaryproxyexecution#certificaterevocationgapActorsGroup123 · Venus 121IOCf23 · i5 · d2 · u0MITRE16
FILEMembersMay 30, 2026, 01:34 (UTC+9)Frozen RAT Builder, Free DNS Alias Keep klovbot Active Since 2017
Sixteen Windows PE32 executables tied to the klovbot malware family are circulating against technology-sector targets in Moldova, and the most operationally revealing detail about the campaign is not the payload — it is the degree to which the operator has changed almost nothing since at least 2017. Three of those files carry enough metadata for deep analysis, and what that analysis surfaces is a tradecraft combination that has outlasted most of the defensive signatures written against it: an…
#klovbot#DarkKomet#XRed#dynamicDNS#Moldova#technologysector#sandboxevasion#USBspreaderIOCf16 · i1 · d0 · u0MITRE24RegionsMDIndustriesTechnology
C&CMembersMay 30, 2026, 00:50 (UTC+9)Sequential C2 Panel Paths Expose Seychelles-Registered Bulletproof Hosting Behind Spain Infostealer Campaign
Three new command-and-control IP addresses have surfaced in the latest observation window of a SmokeLoader and Rhadamanthys infostealer campaign targeting victims in Spain — and the way those addresses were provisioned tells a more precise story than the malware families themselves. Two of the IPs share a single autonomous system number, AS202412, registered to Omegatech LTD, a Seychelles-incorporated entity whose RIPE NCC address block allocations were created within a single month of each…
#SmokeLoader#Rhadamanthys#bulletproofhosting#credentialtheft#Spain#cryptocurrencywallettheft#C2infrastructure#infostealerActorsAPT28 · StrontiumIOCf34 · i3 · d0 · u4MITRE49RegionsES
APTMembersMay 30, 2026, 00:33 (UTC+9)SmokeLoader Campaign Adds Trojanized Card-Checker Lure, Third C2 Node
Since CTX Team's earlier coverage of this SmokeLoader-driven infostealer operation, seven new file indicators have surfaced alongside a full refresh of the campaign's three command-and-control IPs — and the most significant development is not the infrastructure update but what it reveals about how the operator is now getting onto victim machines.
#SmokeLoader#trojan.marsilia#APT39#infostealer#bulletproofhosting#Spain#cryptocurrencytheft#logmarketplaceActorsAPT39 · ChaferIOCf35 · i3 · d0 · u5MITRE48RegionsES
C&CMembersMay 29, 2026, 20:56 (UTC+9)Six-Year-Old Phorpiex Dropper Hits Kazakhstan on Fresh Romanian VPS
A 412-kilobyte Windows executable — unsigned, packed, and masquerading as a tape-toolbar utility from the year 2000 — has been actively beaconing to a freshly provisioned Romanian virtual private server since at least March 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan.
#Phorpiex#ClipBanker#USBworm#Kazakhstan#educationsector#governmentsector#clipboardhijacking#commoditybotnetIOCf8 · i1 · d0 · u10MITRE36RegionsKZIndustriesEducation & Research · Government
APTMembersMay 29, 2026, 19:27 (UTC+9)Two Shell Companies, Two DigiCert Certs, One Ludashi Campaign
Twenty Windows executables and DLLs carrying currently-valid DigiCert code-signing certificates are circulating across telecom-sector endpoints, each one disguised as a routine Windows system utility — a PC cleaner, a BSOD repair tool, a browser protection suite — and each one backed by a C2 cluster that routes through China Unicom's backbone while presenting financial-services TLS cover.
#FIN6#TA428#lockergoga#ncctrojan#lummastealer#TelecommunicationsActorsFIN6 · Skeleton SpiderIOCf29 · i2 · d4 · u4MITRE6IndustriesTelecommunications
APTMembersMay 29, 2026, 18:20 (UTC+9)Revoked Certum Cert Evades 75 of 76 Engines in Ludashi Adware Pivot
Two freshly minted Windows executables, both signed by a previously unseen Chinese entity called 深圳市禹仁科技有限公司 and both carrying a Certum code-signing certificate that had already been revoked at the time of deployment, surfaced on VirusTotal on 23 May 2026 — just six days before CTX Team's analysis. One of the two files, a 346-kilobyte PE32 executable installed under C:\Program Files (x86)\ProZip\Bin\nhlj32.exe, was flagged by exactly one of 76 scanning engines.
#FIN6#SaltySpider#lockergoga#lummastealer#salityActorsFIN6 · Skeleton SpiderIOCf26 · i11 · d10 · u8MITRE16
APTMembersMay 29, 2026, 17:53 (UTC+9)Four Shell Companies, One CA: How Ludashi Buries Payloads in Trusted Certs
Seventeen Windows executables and DLLs. Four distinct Chinese corporate identities. A single DigiCert intermediate certificate authority threading through all of them. That is the structural core of a Ludashi adware and trojan campaign that CTX Team has been tracking across a ten-month payload timeline stretching from July 2025 through late May 2026 — a campaign that uses rotating shell-company code-signing certificates, deliberate PE header corruption, and a pre-staged CDN infrastructure built…
#PatchworkActorsPatchwork · ChinastratsIOCf20 · i8 · d10 · u52MITRE18
FILEMembersMay 29, 2026, 14:42 (UTC+9)Single Sectigo EV Certificate Signs Four Malicious Payloads in One Batch
Four malicious Windows executables — spanning PE32, PE32+, and MSI formats, collectively masquerading as a legitimate system utility suite called "Advanced Windows Manager" — were signed with a single valid Sectigo Extended Validation code-signing certificate in one batch event on the morning of 23 April 2026. The certificate, issued to an entity named "ORYON TECH LIMITED" under the Sectigo Public Code Signing CA EV R36 chain (serial 21 E3 D5 C7 00 22 7E A0 2E E6 84 AF 4F 8F 88 40, thumbprint…
#ORYONTECHLIMITED#GCleaner#EvilCh/CryptOne#pay-per-install#EVcertificateabuse#code-signing#Egypt#UnitedKingdomIOCf23 · i1 · d3 · u7MITRE48RegionsEG · GBIndustriesTechnology
C&CMembersMay 29, 2026, 14:28 (UTC+9)PBot Stealer Gets 64-Bit Rebuild, Drops to 9/76 Detections
Since CTX Team's earlier coverage of this VPN-lure PBot stealer campaign, the most operationally significant development is not the expansion of the domain or IP set — though both have grown substantially — but a single freshly compiled binary that signals the operator is actively retooling the payload build pipeline rather than coasting on existing artifacts.
#ramnit#beaconIOCf9 · i28 · d51 · u6MITRE23
APTMembersMay 29, 2026, 10:16 (UTC+9)Ludashi Campaign Expands C2 Layer With Cloud Proxy Evasion
Since CTX Team's earlier coverage of this campaign, the observable payload set has contracted while the network infrastructure has expanded dramatically — 21 new IP addresses, six new C2 domains, and seven new URLs have entered the picture, with zero new file payloads added. The delta is entirely in the network layer, and what it reveals is a meaningful escalation in how the operators route and obscure their command-and-control traffic.
#TA551#icedidActorsTA551 · ShathakIOCf19 · i21 · d6 · u7MITRE12
APTMembersMay 29, 2026, 10:04 (UTC+9)Emotet Revives 18-Year-Old Domains in Coordinated Chile Campaign
Three .com domains registered between November 2007 and January 2008 — old enough to predate the iPhone's first software update cycle — have been quietly reactivated as payload-staging and command-and-control nodes for an Emotet-linked campaign targeting Chile. The reactivation was not gradual. Between 17 April and 4 May 2026, all three domains received fresh 89-day Let's Encrypt certificates within a compressed 17-day window, a coordinated provisioning pass that CTX Team's analysis identifies…
#EmotetGroup#emotetActorsEmotet Group · TA542IOCf3 · i2 · d3 · u6RegionsCL
APTMembersMay 29, 2026, 09:53 (UTC+9)Trojanised Dr.Fone Installer Delivers VjW0rm via Three-Continent CDN-Masquerade C2
Nine new file indicators and one additional command-and-control IP have been added to the TA2541-linked VjW0rm cluster since earlier coverage, expanding a campaign whose most operationally distinctive feature was never the payload itself but the infrastructure architecture surrounding it: three geographically dispersed servers, each presenting a wildcard-SAN TLS certificate impersonating a different major CDN brand, observed within a 48-hour window and spread across three separate autonomous…
#TA2541#VjW0rm#CDNimpersonation#NSISdropper#JavaScriptworm#C2infrastructure#EgyptFranceRomaniaUnitedStates#OperationLayoverActorsTA2541 · Operation LayoverIOCf17 · i3 · d1 · u2RegionsEG · FR · RO · US
FILEMembersMay 29, 2026, 06:45 (UTC+9)One .NET Builder, Two Malware Families, One Turkish C2 IP
A single PE import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the forensic thread that ties together what initially appears to be two separate commodity malware campaigns. On one end sits a 239-kilobyte AgentTesla infostealer, first submitted to VirusTotal in December 2025 and confirmed malicious by all three sandboxes that analysed it.
#agenttesla#HospitalityLeisure#TechnologyIOCf21 · i1 · d0 · u1MITRE41RegionsMA · TRIndustriesHospitality & Leisure · Technology
APTMembersMay 29, 2026, 05:53 (UTC+9)One Unrevoked Certificate, 18 Builds: Inside a 14-Month Adware Campaign
A DigiCert code-signing certificate issued to a Chengdu technology company has been used continuously for more than 14 months to sign trojanized Windows executables masquerading as components of LuDaShi (鲁大师), one of China's most widely installed PC-optimization suites — and that certificate remains unrevoked today. CTX Team's latest sweep of the campaign has surfaced 41 new file indicators alongside a purpose-built command-and-control domain pair registered in December 2025 that carries a 0/91…
#FIN6#TA428#Group123#lockergoga#ncctrojan#lummastealerActorsFIN6 · Skeleton SpiderIOCf60 · i27 · d4 · u1MITRE13
FILEMembersMay 29, 2026, 02:45 (UTC+9)Packed .NET Stealer Hits Healthcare in 7 Countries With Sandbox-Aware Evasion
A 593-kilobyte .NET assembly, unsigned and unremarkable in appearance, has been circulating against healthcare organisations across Belgium, India, Italy, Sri Lanka, Pakistan, Tunisia, and the United States since at least March 2026. What makes it analytically interesting is not its payload — credential theft is commodity work — but the layered effort its operators invested in making sure analysts never get a clean look at it.
#HealthcareIOCf3 · i1 · d0 · u1MITRE24RegionsBE · IN · IT · LKIndustriesHealthcare
APTMembersMay 29, 2026, 01:53 (UTC+9)Three DigiCert Certs, One Builder: Inside a Chinese Adware Signing Pipeline
Somewhere between a disk-cleaner utility and a remote-access implant, a modular Windows toolkit has been quietly circulating across Chinese software distribution channels, its every component bearing a valid DigiCert code-signing certificate issued to a registered Chinese legal entity. The campaign — tracked by CTX Team across at least 41 PE32 files and 20 confirmed network endpoints — deploys under four consumer-software personas (DupsClean, LargeFileClean, BirdWallpaper, and BlueDoveUnist)…
#APT33#shapeshift#icedidActorsAPT33 · MagnalliumIOCf41 · i77 · d3 · u2MITRE15
FILEMembersMay 28, 2026, 23:13 (UTC+9)Amadey Loader Hits Academic Networks Across 11 Countries via IE5 Cache
A freshly submitted Win32 executable — unsigned, just over 2 MB, first observed on VirusTotal on 2026-05-07 — is delivering a credential-harvesting payload to education and research institutions across eleven countries, using a staging chain that exploits legacy Internet Explorer cache paths, embeds a secondary payload in the binary's overlay section, and beacons home over raw HTTP to a single IPv4 address on a Seychelles-registered autonomous system that was provisioned less than nine months…
#APT28#EducationResearchActorsAPT28 · StrontiumIOCf2 · i1 · d0 · u1MITRE25RegionsBA · BO · CO · INIndustriesEducation & Research
FILEMembersMay 28, 2026, 22:59 (UTC+9)Expired 2017 Certificate Still Powers Process Hacker 2 Offensive Toolkit
Seventeen Windows executables — two main GUI binaries, a kernel-mode driver, a PE viewer, and thirteen plugin DLLs — have been assembled into a unified offensive package and are circulating with Authenticode signatures that expired in January 2017. The signing identity is "Wen Jia Liu," issued under two DigiCert certificate serials that together bind every file in the toolkit to a single developer lineage.
#RoyalRansomware#CommentCrew#glasses#prochackActorsRoyal Ransomware · Team OneIOCf19 · i0 · d0 · u0MITRE10
C&CMembersMay 28, 2026, 22:40 (UTC+9)Trojanized Security Suite Uses Valid DigiCert Cert to Blind Sandboxes
Nine PE32 components masquerading as a legitimate Chinese consumer security product are circulating with a currently-valid DigiCert code-signing certificate, a direct-syscall evasion technique confirmed by YARA, and payload delivery routed through Alibaba's KunlunCan CDN — a combination that collapses sandbox verdicts to zero while roughly half of antivirus engines still flag the files on static analysis alone. The gap between those two numbers is the operational story of this campaign.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf9 · i21 · d2 · u5MITRE22
C&CMembersMay 28, 2026, 22:28 (UTC+9)One DigiCert Cert, 14 Executables, Nine Months Undetected
Fourteen distinct Windows executables. Six different product personas. One code-signing certificate — and nine months of continuous, largely undetected operation. That is the operational picture CTX Team has assembled from a cluster of signed PE32 binaries circulating through the Ludashi PUA distribution ecosystem, all stamped with a single DigiCert certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid through 2027-05-20).
#FIN6#Group123#SaltySpider#lockergoga#salityActorsFIN6 · Skeleton SpiderIOCf23 · i25 · d4 · u1MITRE11
APTMembersMay 28, 2026, 21:56 (UTC+9)Dual DigiCert Certs Cloak Adware-to-RAT Campaign Across 19 Payloads
##A Single Certificate, Nineteen Signed Payloads, and a RAT Hidden Inside an Adware Framework Nineteen Windows binaries carrying valid DigiCert code-signing certificates — issued to two distinct Chinese-registered entities — have been circulating across Mandarin-language software distribution channels for at least eight months, wrapping a Ludashi/PolarWind adware framework around a RAT-capable core that most endpoint products still cannot see clearly.
#FIN6#TA428#APT23#lockergoga#ncctrojan#lummastealerActorsFIN6 · Skeleton SpiderIOCf61 · i5 · d3 · u3MITRE20
FILEMembersMay 28, 2026, 19:00 (UTC+9)Fake Windows DLL Targets Singapore Construction Firms in 16-Year Campaign
A 43-kilobyte Windows DLL masquerading as the operating system's own language-pack library is at the centre of an active implant chain targeting Singapore's construction sector — a toolkit that combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence into a layered evasion architecture that has remained operationally relevant from its first recorded submission in July 2010 through at least May 2026.
#GoblinPanda#avzhan#ConstructionActorsGoblin Panda · CycldekIOCf2 · i0 · d0 · u0MITRE23RegionsSGIndustriesConstruction
FILEMembersMay 28, 2026, 18:49 (UTC+9)Signed VPN Installer Trojan Targets Food and Beverage Firms
Three Windows executables — VPNMaster.exe, Startup.exe, and master_vpn-service.exe — are circulating as components of a coherent VPN product installation, each carrying a DigiCert G4 code-signing certificate issued to a Singapore-registered entity called "INNOVATIVE CONNECTING PTE. LIMITED." The certificate, serial number 0C 8F 89 21 C5 36 49 3E 67 DF 84 FB 82 23 B0 92, expired on 2 April 2026, yet the binaries remain structurally signed and continue to bypass security controls on systems that…
#Barium#APT15#Cactus#ramnit#FoodBeveragesActorsBarium · Wicked SpiderIOCf14 · i1 · d6 · u1MITRE7IndustriesFood & Beverages
C&CMembersMay 28, 2026, 18:31 (UTC+9)One EV Certificate, Two Trojans, Three Fake Windows Binaries
Two trojan.jumper payloads circulating under the guise of a WireVPN client share an identical GlobalSign Extended Validation code-signing certificate — serial 03 A9 18 8A A5 10 C0 F8 34 34 26 BF, issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED — while three companion files masquerade as canonical Windows system executables, carrying valid Microsoft signatures and zero detections across 76 scanning engines.
#beacon#AutomotiveIOCf6 · i6 · d6 · u0MITRE12IndustriesAutomotive
C&CMembersMay 28, 2026, 18:11 (UTC+9)Space Pirates Add Signed .NET Stealer to Trojanized-VPN Arsenal
Since CTX Team's earlier coverage of this campaign, eight new malicious files and a complete refresh of 18 IP addresses and 26 domains have surfaced — but the most operationally significant development is not the scale of the infrastructure turnover. It is the addition of a third signed-binary abuse vector: a Dotfuscator-packed, encrypted .NET stealer classified as PBot, hidden inside a binary carrying a valid Bright Data Ltd code-signing certificate.
#SpacePirates#ramnit#beaconActorsSpace Pirates · WebwormIOCf14 · i18 · d26 · u4MITRE17
FILEMembersMay 28, 2026, 14:45 (UTC+9)APT28's Three-Signer Chain Leaves Four Files at Zero Detections
Eight Windows executables. Three separate trusted signing identities. Four files sitting at zero detections across 76 antivirus engines. The campaign that CTX Team has been tracking under the RostPay/RostDown family designation is not a blunt-force intrusion operation — it is a methodical exercise in trust subversion, engineered so that the failure of any single certificate or detection rule leaves at least two other evasion layers intact.
#APT28#nitol#ghost#CommercialActorsAPT28 · StrontiumIOCf8 · i2 · d0 · u0MITRE11IndustriesCommercial Services
FILEMembersMay 28, 2026, 10:58 (UTC+9)XWorm Campaign Expands to Three-Channel C2 Fabric Across Offshore ASNs
Since CTX Team's earlier coverage of this XWorm campaign, two freshly provisioned command-and-control nodes have surfaced in RIPE NCC address space allocated in late 2025 — 158.94.209.22 under ASN 202412 (Omegatech LTD, Seychelles-registered) and 143.20.134.59 under ASN 215703 (Freakhosting Ltd, nominally UK-registered) — alongside a new dynamic DNS endpoint, jar5.ydns.eu, that carries no VirusTotal detection data at all.
#Commercial#Government#Manufacturing#Media#SupportServiceActivities#TechnologyIOCf12 · i2 · d0 · u1MITRE33RegionsAT · BE · BS · CAIndustriesCommercial Services · Government · Manufacturing
C&CMembersMay 28, 2026, 06:11 (UTC+9)Ludashi PUA Pivots to Cloud-Fronted C2 via Tencent API Gateway
Since CTX Team's earlier coverage of the Ludashi PUA campaign, the observable infrastructure has undergone a complete turnover: twelve new IP addresses, six new domains, and seven new URLs have entered the active indicator set, while every previously tracked file has rotated out. The payload layer is quiet — zero new binaries — but the network layer tells a story of deliberate, operationally sophisticated infrastructure replacement.
#TA551#icedidActorsTA551 · ShathakIOCf19 · i12 · d6 · u7MITRE12
APTMembersMay 28, 2026, 05:53 (UTC+9)Signed DLL in Adware Chain Confirmed as PubNubRAT
For eighteen months, a campaign built around two DigiCert code-signing certificates issued to Chengdu-registered entities moved through Chinese-language Windows environments largely beneath the noise floor — its payloads labelled adware, its delivery mechanism a well-known PC-utility ecosystem, its detection rates low enough that signed binaries slipped past Windows SmartScreen with detection ratios as low as 10 of 77 engines. That picture changed with the appearance of a single DLL.
#APT23#lummastealerActorsAPT23 · KeyBoyIOCf28 · i26 · d2 · u3MITRE13
FILEMembersMay 28, 2026, 02:47 (UTC+9)KMSpico Trojan Chain Delivers LummaStealer to Kenya's Tech Sector
Four Windows executables carrying the same self-issued code-signing certificate have been circulating as KMSpico software activators for nearly a decade — and CTX Team's analysis of a recently surfaced indicator cluster shows that the same @ByELDI Certificate Authority, serial number CB C9 53 5C 7A 4B 70 DE 52 6C 01 39 FE AF 2C 9C, still binds the distribution chain today.
#LazarusGroup#lummastealer#TechnologyActorsLazarus Group · Hastati GroupIOCf17 · i1 · d0 · u0MITRE42RegionsKEIndustriesTechnology
FILEPublicMay 28, 2026, 02:32 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Telecom Cryptomining Campaign
Compiled on April 16, 2026, and submitted to VirusTotal just two days later, an unsigned 2.5-megabyte Windows executable is doing something that should give pause to every security team protecting telecommunications infrastructure: it is loading a kernel driver that was signed in 2008, whose Authenticode certificate expired that same year, and whose vulnerabilities have been publicly catalogued for years — and using that driver to claw its way to ring-zero privilege before beaconing out to a…
#LazarusGroup#BYOVD#WinRing0x64#cryptomining#telecommunications#LOLDrivers#privilegeescalation#HashVaultActorsLazarus Group · Hastati GroupIOCf4 · i1 · d0 · u0MITRE31RegionsAR · BG · BR · GRIndustriesTelecommunications
C&CMembersMay 28, 2026, 02:13 (UTC+9)Fake Speed-Test Utility Hides Eight-Year C2 Network With *.malware.com Cert
Two subdomains. One IP address. One self-signed TLS certificate whose common name is literally *.malware.com. The infrastructure behind a shlayer-attributed potentially unwanted program (PUP) campaign targeting the energy sector is not subtle — but its longevity is. The parent domain buffernavpose.com was registered on 2018-05-12 via Dynadot Inc, has been actively maintained through at least April 2026, and carries a certificate valid until 2030-05-11.
#shlayer#EnergyIOCf2 · i0 · d2 · u10MITRE15IndustriesEnergy
APTMembersMay 28, 2026, 01:59 (UTC+9)Ludashi Campaign Adds 13 Payloads, Tencent CDN Relay to Evasion Stack
Thirteen new Windows PE32 binaries signed under a single DigiCert code-signing certificate have entered the Ludashi-ecosystem campaign since CTX Team's prior coverage, while a freshly provisioned four-subdomain C2 cluster under tjbxldkj.cn and a Tencent Cloud API Gateway domain-fronting relay on ss.dllfix.cn represent infrastructure capabilities that were absent from the earlier operation.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf32 · i23 · d6 · u8MITRE12
C&CMembersMay 27, 2026, 21:54 (UTC+9)Six-Year-Old Batch Script Powers 2025 Telecom Espionage Campaign
A trojanised ZIP archive impersonating the legitimate Microsoft Activation Scripts open-source project is circulating across enterprise endpoints, embedding active sandbox-evasion logic inside what victims perceive as a trusted Windows activation utility — and funnelling compromised hosts toward a freshly constructed, deliberately compartmentalised command-and-control infrastructure spanning three distinct autonomous systems with no cross-node certificate or DNS linkage between them.
#TA505#Cactus#goldeneye#TelecommunicationsActorsTA505 · Hive0065IOCf2 · i2 · d1 · u17MITRE4IndustriesTelecommunications
C&CMembersMay 27, 2026, 18:11 (UTC+9)WireVPN Campaign Adds 132 Domains and a PBot Stealer Component
Fifty-five new command-and-control IPs and 132 additional domains have joined the Trojan.Jumper/WireVPN campaign's observable footprint since CTX Team's earlier coverage, transforming what was a 15-domain, 9-ASN operation into a multi-continent hosting fabric organised across five named fingerprint clusters. The expansion is not random: every cluster is bound by a shared certificate issuer, autonomous system, or registrar identity, and the core payload chain — three PE32 executables all signed…
#SpacePirates#CactusActorsSpace Pirates · WebwormIOCf4 · i55 · d132 · u19MITRE14
C&CMembersMay 27, 2026, 17:56 (UTC+9)Salty Spider Expands to Dual-Domain C2 With UnionPay TLS Fingerprint
Nine command-and-control domains, nine documented URL paths, and 31 IP addresses — none present in prior coverage — have surfaced in the latest observed activity tied to the Salty Spider campaign, exposing for the first time the full operational infrastructure behind a signed-binary adware toolkit that CTX Team has been tracking across multiple observation windows.
#SaltySpider#lummastealer#salityActorsSalty Spider · KuKuIOCf51 · i31 · d9 · u9MITRE8
C&CMembersMay 27, 2026, 13:52 (UTC+9)Trojan.Jumper Builds Five-Tier C2 Across 15 Domains and 9 ASNs
Fifteen new domains. Nine IP addresses spanning six autonomous systems across four continents. Five distinct certificate-issuer fingerprints provisioned within a 45-day window. Since CTX Team's earlier coverage of the Trojan.Jumper campaign, the operator has not merely maintained an existing footprint — they have constructed a layered, multi-tier command-and-control architecture that reveals a level of infrastructure investment inconsistent with opportunistic or low-sophistication adversaries.
#GovernmentIOCf4 · i9 · d15 · u4MITRE18IndustriesGovernment
FILEMembersMay 27, 2026, 10:29 (UTC+9)One Imphash, Two Malware Families: Inside a Shared .NET Builder
A purchase-order-themed spear-phishing campaign active since mid-May 2026 has delivered something more operationally revealing than its commodity tooling alone would suggest: two functionally distinct malware families — XWorm RAT and AgentTesla infostealer — sharing an identical PE import-table hash (imphash f34d5f2d4577ed6d9ceec516c1f5a744) and the same PEiD packer signature, confirming both were produced by a single .NET builder kit or shared loader stub.
#agenttesla#Automotive#Commercial#Construction#EducationResearch#EnergyIOCf9 · i1 · d0 · u1MITRE53RegionsAT · AU · BD · BEIndustriesAutomotive · Commercial Services · Construction
FILEPublicMay 27, 2026, 06:47 (UTC+9)Gamaredon Hides Credential-Stealer in Trojanized Driver Utility
A 39-megabyte Windows installer masquerading as the legitimate Easeware DriverEasy driver-update utility is circulating with a forged compile timestamp, a near-maximum-entropy resource section concealing an encrypted payload, and two Dotfuscator-obfuscated .NET implant components built in the same toolchain session — a layered evasion architecture that CTX Team has attributed to Gamaredon Group and linked to construction-sector targeting.
#GamaredonGroup#gamaredon#ConstructionActorsGamaredon Group · CTIGIOCf4 · i0 · d0 · u0MITRE27IndustriesConstruction
APTMembersMay 27, 2026, 06:02 (UTC+9)Trojanised Office Tool Hides Multi-Stage Intrusion Behind Streaming C2
A trojanised version of OfficeRTool — a popular Microsoft Office removal and activation utility distributed through piracy channels — is serving as the entry point for a disciplined, multi-phase intrusion operation that layers sandbox-evading VBScript components, a vhash-identical PowerShell downloader maintained across at least six major tool versions, expired-certificate network reconnaissance, and a command-and-control channel engineered to look indistinguishable from HLS media streaming…
#LockbitGang#expiro#GovernmentActorsLockbit GangIOCf7 · i3 · d2 · u8MITRE11IndustriesGovernment
APTMembersMay 27, 2026, 05:51 (UTC+9)Expired-Cert Installer Evades Sandboxes, Feeds 15-Domain Crypto Fraud Net
A 4.3-megabyte Windows installer, dressed in the branding of legitimate freeware and carrying a Sectigo-issued code-signing certificate that had already expired, is the entry point for a financially motivated campaign that routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains.
#APT28#APT15#bumblebee#EnergyActorsAPT28 · StrontiumIOCf62 · i6 · d15 · u11MITRE12IndustriesEnergy
FILEMembersMay 27, 2026, 01:21 (UTC+9)XWorm Worm Campaign Hits 24 Countries via Spanish Quotation Lure
A 914-kilobyte Windows executable masquerading as a Spanish-language purchase-order request is circulating across 24 countries, carrying a payload combination that goes well beyond what most commodity-RAT deployments attempt: XWorm and PureLog Stealer bundled together, wrapped in a PEiD-packed binary with a .text section entropy of 7.83, and equipped with a worm-propagation module that can copy the infection to removable media without any additional operator action.
#BusinessAssociations#Chemicals#Construction#Engineering#Government#ManufacturingIOCf12 · i2 · d0 · u1MITRE32RegionsAT · BE · CA · CHIndustriesBusiness Associations · Chemicals · Construction
FILEMembersMay 27, 2026, 00:53 (UTC+9)APT28 Hides Espionage Chain Inside Piracy Activation Toolkit
Seventeen files. One freshly minted domain. A Moldovan hosting provider with a near-clean reputation score. On the surface, the package looks like something millions of Windows users have downloaded without a second thought: a piracy toolkit for activating unlicensed Microsoft software. Look past the familiar filenames and the campaign reveals something considerably more deliberate — a multi-layer espionage delivery chain attributed by CTX Team to APT28, the Russian state-aligned threat actor…
#APT28#powershell#TelecommunicationsActorsAPT28 · StrontiumIOCf17 · i1 · d1 · u0MITRE15IndustriesTelecommunications
APTMembersMay 27, 2026, 00:03 (UTC+9)APT28 Splits EV Certificate and LummaC2 Stealer Across Two-Tier Chain
Four Windows executables carrying a valid Extended Validation code-signing certificate issued to an entity called ORYON TECH LIMITED are circulating as a disguised system-utility package — while a pair of freshly compiled LummaC2 stealers, deliberately stripped of any trusted certificate chain, rides the same delivery infrastructure toward the same targets. The deliberate split is not an oversight.
#APT28#gcleaner#TechnologyActorsAPT28 · StrontiumIOCf21 · i2 · d5 · u8RegionsUSIndustriesTechnology
APTMembersMay 26, 2026, 23:45 (UTC+9)Signed, Sealed, Trojanized: Dual Chengdu Certs Power RAT Campaign
Eighteen Windows PE32 files — executables and DLLs impersonating Ludashi SuperApp system utilities — are circulating with currently-valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, producing uniformly clean sandbox verdicts despite industry detection ratios that reach as high as 34 of 76 engines.
#Turla#FIN6#Group123#lockergoga#ncctrojan#xtreme_ratActorsTurla · Iron HunterIOCf57 · i27 · d7 · u1MITRE16IndustriesTelecommunications
C&CMembersMay 26, 2026, 22:40 (UTC+9)One DigiCert Cert Signed 16 Malicious Binaries Across 18 Months
Sixteen distinct Windows binaries. Eight separate product personas. One DigiCert code-signing certificate — and not a single revocation in eighteen months. That is the operational core of a sustained adware and data-harvesting campaign that CTX Team has been tracking across the Ludashi (鲁大师) software ecosystem, where malware dressed as Chinese security utilities has been circulating since at least November 2024.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf30 · i25 · d9 · u9MITRE12