
APT28's Three-Signer Chain Leaves Four Files at Zero Detections
A campaign tied to APT28 deploys a RostPay/RostDown downloader pair under a GlobalSign EV certificate issued to a Russian LLC, then stages post-access tools as Microsoft-signed Windows LOLBins with appended overlay payloads. The layered architecture — spanning three independent certificate authorities and a PyInstaller implant hiding behind a valid Intel signing identity — is engineered so that defeating any single evasion layer leaves the others fully intact.
Eight Windows executables. Three separate trusted signing identities. Four files sitting at zero detections across 76 antivirus engines. The campaign that CTX Team has been tracking under the RostPay/RostDown family designation is not a blunt-force intrusion operation — it is a methodical exercise in trust subversion, engineered so that the failure of any single certificate or detection rule leaves at least two other evasion layers intact.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read