
APT10's 2016 ChChes Implant Runs on C2 Renewed in 2025
A Windows implant compiled in November 2016 carries a code-signing certificate expired since 2012, yet its command-and-control domain received a fresh TLS certificate in September 2025. CTX Team's analysis of the ChChes sample finds layered evasion targeting static trust checks, sandbox timing, and protocol-aware network inspection — with infrastructure someone is still actively maintaining.
A 283-kilobyte Windows executable compiled in November 2016 carries a code-signing certificate that expired more than a decade ago — yet the command-and-control domain it phones home to received a fresh TLS certificate as recently as September 2025. That tension between aged tooling and actively maintained infrastructure is the defining characteristic of a ChChes implant attributed to Red Apollo (APT10) that CTX Team has been tracking since December 2024.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read