APTMembers
APT

Two Adware Families Share One GlobalSign EV Cert Chain

A feed labeled this cluster APT28 espionage tooling, but VirusTotal enrichment resolves it to two unrelated adware installers and a recycled redirect-gate infrastructure. The one solid link between them is a shared GlobalSign EV code-signing intermediate — not shared authorship, but a common certificate supply chain.

Jul 14, 2026, 13:34 (UTC+9)Last seenJul 14, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC25MITRE24

Two commodity adware installers with nothing else in common — different file types, different packers, different threat labels, submitted sixteen months apart — chain to the exact same GlobalSign intermediate certificate. That single overlap, buried inside a feed-tagged "APT28" cluster, turns out to be the most concrete, independently verifiable signal in the entire dataset, and it has nothing to do with espionage tradecraft.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence