C&CMembers
C&C

Fake VPN Installer, IR-Aware Beacon, Forged Signature Tie to One Server

A trojanized VPN installer, a code-signed-but-untrusted trojan, and a reverse-shell beacon that checks for forensic tools share no build artifacts with each other — yet all three point to a single certificate-linked C2 node. The technique chain, from fake-installer lure to self-IP recon to beacon execution, is what makes this small toolkit notable, not its sophistication.

Sep 5, 2026, 22:27 (UTC+9)Last seenSep 5, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC38RegionsCHJOTW

A fake VPN installer that a leading sandbox rated 97% "clean," a reverse-shell beacon built to notice when incident responders are watching, and a 6-megabyte trojan that dresses itself in a code signature no root authority will vouch for — three unrelated builds, no shared imphash, no shared signer, converging on a single certificate-linked server.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence