C&CMembers
C&C

A Certificate for Every Stage: How DustSquad Weaponized Three Trust Systems

A DustSquad-tagged infrastructure set uses certificates as its core tradecraft at every stage of the kill chain: a revoked EV code-signing chain behind two adware bundlers, a three-day Microsoft-verified certificate wrapping a VPN-branded credential stealer, and cloned Akamai/Alibaba TLS certificates fronting command-and-control nodes on two continents. No single certificate event stands out; the significance is in the compounding pattern across delivery, evasion, and C2.

Aug 20, 2026, 22:46 (UTC+9)Last seenAug 20, 2026Severity100ByCTX TeamActorDustSquadAPTC34IOC18

Two adware installers signed under a code-signing certificate that was later revoked. A VPN-branded credential stealer signed under a Microsoft-verified chain whose leaf certificate was valid for exactly three days. A pair of command-and-control nodes on two different continents, each wearing a TLS certificate cloned to look like Akamai or Alibaba Cloud.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence