C&CMembers
C&C

APT28 Deploys Validly Signed Chrome Fake, Gets Zero Detections

A Windows executable impersonating Google Chrome carries a valid, unexpired Google LLC code-signing certificate — and cleared all 76 antivirus engines that examined it. The campaign pairs it with a BitTorrent-signed dropper and a three-domain C2 architecture built for both persistence and rapid rotation.

May 24, 2026, 14:51 (UTC+9)Last seenMay 24, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC12MITRE4

A 4-megabyte Windows executable masquerading as Google Chrome is circulating with a valid, unexpired Google LLC code-signing certificate — and every one of the 76 antivirus engines that examined it returned a clean verdict. That single data point, drawn from CTX Team's analysis of a cluster attributed to APT28 (also tracked as Fancy Bear, Forest Blizzard, and approximately 17 other aliases), captures the operational logic of the entire campaign: when a binary carries a legitimate certificate…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence