
Cactus Group Abuses Three Signing Identities to Hide PBot Stealer in VPN Lures
A campaign attributed to the Cactus group exploits expired EV and OV code-signing certificates on trojanized VPN installers and a valid commercial SDK signature to deliver the PBot credential stealer. The operation simultaneously enrolls victim machines in a residential proxy network, combining immediate credential theft with long-term infrastructure monetisation. A disposable C2 layer of Chinese-registered phishing domains and a Russia-hosted developer-platform decoy complete the architecture.
Nine Windows executables circulating across software-distribution channels share a single operational logic: every one of them carries a legitimate code-signing certificate — or a certificate that was legitimate until recently — and every one of them is doing something the signer never intended. Six files exploit expired-but-chain-valid EV and OV certificates from two distinct corporate identities to suppress antivirus detection on trojanized VPN installers.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read