APTMembers
APT

Decade-Old Keygen Trojan Anchors Multi-Stage Pakistan Espionage Chain

Six newly surfaced files expose the full delivery and execution scaffolding behind the Godzilla Loader and PonyStealer campaign targeting Pakistan. A batch-script orchestrator, an invalid-signed SOCKS5 proxy tool, a PEiD-packed spreader, and a keygen lure active since 2015 complete a multi-layer drop chain that was only partially visible before. Six additional kanorgate.php C2 URLs now activate all three .ru domains simultaneously, confirming an expanded redundancy architecture.

Jun 26, 2026, 01:23 (UTC+9)Last seenJun 26, 2026Severity100ByCTX TeamIOC31MITRE34RegionsPK

Since CTX Team's earlier coverage of this operation, six new files have surfaced that materially deepen the picture of how the Godzilla Loader and PonyStealer campaign targeting Pakistan actually functions — not just what it delivers, but how it gets there. The new components introduce a second build cluster absent from prior analysis: a batch-script orchestrator, an invalid-signed SOCKS5 proxy tool, a PEiD-packed .NET spreader, and a delivery archive built around a keygen lure that has been…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence