
APT28 Splits EV Certificate and LummaC2 Stealer Across Two-Tier Chain
Four Windows executables bearing a live Sectigo Extended Validation certificate issued to ORYON TECH LIMITED are silently enrolling victims into a residential proxy network, while a separate pair of LummaC2 credential stealers rides the same infrastructure with deliberately broken certificate chains. The split is architectural: the operators are protecting their signed delivery layer from revocation events that could burn the stealer track, and vice versa.
Four Windows executables carrying a valid Extended Validation code-signing certificate issued to an entity called ORYON TECH LIMITED are circulating as a disguised system-utility package — while a pair of freshly compiled LummaC2 stealers, deliberately stripped of any trusted certificate chain, rides the same delivery infrastructure toward the same targets. The deliberate split is not an oversight.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read