FILEMembers
FILE

APT28 Deploys 11-Year-Old Signed Kernel Driver in Layered Credential-Theft Campaign

A fake HSBC payment notification delivers a three-stage attack chain combining a decade-old signed vulnerable kernel driver, a SspiCli.dll sideloading payload, and an AgentTesla infostealer. The kernel driver, first seen in 2015 and still carrying a legitimate code signature, achieves only 3/76 detection while clearing the path for credential harvesting across ten industries and twenty-three countries.

May 31, 2026, 21:00 (UTC+9)Last seenMay 31, 2026Severity52ByCTX TeamActorAPT28StrontiumIOC43MITRE27RegionsAEATAUBDBR

A financially themed ZIP archive named HSBC_PAYMENT_ADVICE0293845678.zip is circulating as the opening move in a layered attack chain that deploys a signed vulnerable kernel driver first seen in 2015 alongside a freshly compiled DLL sideloading payload and an AgentTesla infostealer equipped with active sandbox-evasion logic.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence