APTMembers
APT

Signed Chinese Input-Method Suite Hides IcedID-Flagged Loader

Four EV-signed binaries branded as a popular Chinese Wubi input method share one build batch and, in two cases, a static IcedID payload signature — despite clean sandbox verdicts. The cluster extends to signed kernel drivers and CDN-impersonating IPs, with medium-confidence ties to APT27.

Jul 31, 2026, 21:36 (UTC+9)Last seenJul 31, 2026Severity100ByCTX TeamActorAPT27TEMP.HippoIOC18MITRE11

Four Windows binaries branded as 万能五笔输入法 — a legitimate Chinese Wubi input-method suite — carry an identical Extended Validation code-signing certificate, the same build timestamp, and, in two cases, a payload signature tied to the IcedID malware family, even though the sandboxes that examined them returned a clean verdict. The pairing of trusted EV signing with a static loader-kit fingerprint that slips past dynamic analysis is the sharpest signal in a nine-file, nine-IP cluster CTX Team has…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence