FILEMembers
FILE

APT28's Three-Signer Chain Leaves Four Files at Zero Detections

A campaign tied to APT28 deploys a RostPay/RostDown downloader pair under a GlobalSign EV certificate issued to a Russian LLC, then stages post-access tools as Microsoft-signed Windows LOLBins with appended overlay payloads. The layered architecture — spanning three independent certificate authorities and a PyInstaller implant hiding behind a valid Intel signing identity — is engineered so that defeating any single evasion layer leaves the others fully intact.

May 28, 2026, 14:45 (UTC+9)Last seenMay 28, 2026Severity82ByCTX TeamActorAPT28StrontiumIOC10MITRE11

Eight Windows executables. Three separate trusted signing identities. Four files sitting at zero detections across 76 antivirus engines. The campaign that CTX Team has been tracking under the RostPay/RostDown family designation is not a blunt-force intrusion operation — it is a methodical exercise in trust subversion, engineered so that the failure of any single certificate or detection rule leaves at least two other evasion layers intact.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence