APTMembers
APT

Trojanized Antivirus Suite Hides C2 in Alibaba CDN for Three Years

Ten Windows DLLs signed in a single four-minute session on 30 August 2023 form the core of a trojanized Chinese-language antivirus suite that routes malicious update traffic through Alibaba's Kunlun CDN, making payloads indistinguishable from routine signature delivery. A valid DigiCert certificate, a six-year-old domain, and CDN blending defeat three common first-line defences simultaneously — and the campaign's delivery infrastructure remained active through at least May 2026.

Jun 2, 2026, 01:04 (UTC+9)Last seenJun 2, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC59MITRE12

Ten malicious Windows DLLs, all signed within a single four-minute window on the morning of 30 August 2023, are circulating as components of a trojanized Chinese-language antivirus suite — and the operators behind them have constructed a delivery chain so thoroughly wrapped in legitimate infrastructure that three of the most common first-line defences fail simultaneously. The certificate is real. The domain is six years old.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence