APTMembers
APT

APT10's 2016 ChChes Implant Runs on C2 Renewed in 2025

A Windows implant compiled in November 2016 carries a code-signing certificate expired since 2012, yet its command-and-control domain received a fresh TLS certificate in September 2025. CTX Team's analysis of the ChChes sample finds layered evasion targeting static trust checks, sandbox timing, and protocol-aware network inspection — with infrastructure someone is still actively maintaining.

Jun 17, 2026, 13:49 (UTC+9)Last seenJun 17, 2026Severity100ByCTX TeamActorRed ApolloPotassiumIOC7MITRE13

A 283-kilobyte Windows executable compiled in November 2016 carries a code-signing certificate that expired more than a decade ago — yet the command-and-control domain it phones home to received a fresh TLS certificate as recently as September 2025. That tension between aged tooling and actively maintained infrastructure is the defining characteristic of a ChChes implant attributed to Red Apollo (APT10) that CTX Team has been tracking since December 2024.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence