
APT28 Deploys Validly Signed Chrome Fake, Gets Zero Detections
A Windows executable impersonating Google Chrome carries a valid, unexpired Google LLC code-signing certificate — and cleared all 76 antivirus engines that examined it. The campaign pairs it with a BitTorrent-signed dropper and a three-domain C2 architecture built for both persistence and rapid rotation.
A 4-megabyte Windows executable masquerading as Google Chrome is circulating with a valid, unexpired Google LLC code-signing certificate — and every one of the 76 antivirus engines that examined it returned a clean verdict. That single data point, drawn from CTX Team's analysis of a cluster attributed to APT28 (also tracked as Fancy Bear, Forest Blizzard, and approximately 17 other aliases), captures the operational logic of the entire campaign: when a binary carries a legitimate certificate…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read