APTMembers
APT

A Decade-Old Adware Builder Wearing an Espionage Label

Four JavaScript files tagged as APT39 espionage tooling turn out to be a single Crossrider-style payload cloned across at least six Chrome extension IDs. The build evidence points to a commodity adware toolkit from 2013, not a nation-state implant.

Aug 10, 2026, 06:35 (UTC+9)Last seenAug 10, 2026Severity62ByCTX TeamActorAPT39ChaferIOC24RegionsGB

Four JavaScript files sitting inside a record tagged "apts" and attributed to APT39 turn out, on inspection of their own build fingerprints, to be the same payload repackaged under at least six different Chrome extension identities — a mass-cloning technique straight out of the Crossrider adware playbook, not a nation-state implant.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence