APTMembers
APT

HijackLoader Hides Behind Real Zalo Code-Signing Certificate

A three-day-old malicious file shares an identical VNG GROUP JSC certificate serial with a clean, much larger legitimate-looking Zalo installer, both signed four minutes apart. Only 3 of 75 engines flagged the loader, while a matching TLS certificate serial ties the campaign's zdn.vn subdomain directly to an FPT Telecom-hosted IP.

Jul 24, 2026, 05:31 (UTC+9)Last seenJul 24, 2026Severity100ByCTX TeamActorTA551ShathakIOC19MITRE13

Three days before this cluster surfaced, a file calling itself Zalo.exe carried a fully valid VNG GROUP JSC code-signing certificate — the same signing identity that legitimate builds of Vietnam's dominant chat app use — and only 3 of 75 engines flagged it. CAPE Sandbox and the crowdsourced YARA rule HijackLoaderStub, firing twice on the sample, both independently identified it as HijackLoader, a loader family that has no business hiding behind a trusted Vietnamese software publisher's…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence