APTMembers
APT

Forged 72-Hour Certificates Hid WarzoneRAT From All 76 AV Engines

A trojanised installer disguised as a legitimate German browser product delivered WarzoneRAT, a Winos4.0 stager, and a SQL Server authentication-bypass implant to targets across Germany, France, and Luxembourg. The entire payload set was signed with two deliberately short-lived Microsoft ID Verified certificates, achieving zero static detections while defeating most automated sandboxes through active evasion logic.

Jun 18, 2026, 15:58 (UTC+9)Last seenJun 18, 2026Severity56ByCTX TeamActorAPT28StrontiumIOC55MITRE55RegionsDEFRLU

Seven Windows executables and DLLs, all signed under the name of a legitimate German digital-publishing company, arrived on VirusTotal on 23 May 2026 with a combined static detection score of zero across 76 engines. The files presented themselves as components of "t-online Browser 7," a real product distributed by Ströer Digital Publishing GmbH — complete with version strings, Mozilla Public License 2.0 copyright notices, and Authenticode signatures rooted in Microsoft's own…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence