C&CMembers
C&C

APT28 Burns Fake Cert, Hides Agent Behind Legit Vendor Signature

A trojanized browser installer signed under the fraudulent identity 'Work Product Inc.' is targeting telecom sector endpoints, while a companion .NET agent signed by a legitimate vendor's certificate evades all 76 antivirus engines. The dual-certificate strategy — one disposable fraudulent identity for delivery, one durable legitimate vendor identity for post-exploitation — is designed so revoking the first certificate leaves the second-stage agent fully intact.

May 26, 2026, 16:51 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC10MITRE6

Two Windows executables, both signed with a freshly minted code-signing certificate issued to a shell identity called "Work Product Inc.," are circulating as a trojanized browser installer targeting the telecom sector — a signed-binary abuse chain [T1553.002] engineered to walk past execution controls before most endpoint tools have a chance to render a verdict.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence