APTMembers
APT

APT28 Splits EV Certificate and LummaC2 Stealer Across Two-Tier Chain

Four Windows executables bearing a live Sectigo Extended Validation certificate issued to ORYON TECH LIMITED are silently enrolling victims into a residential proxy network, while a separate pair of LummaC2 credential stealers rides the same infrastructure with deliberately broken certificate chains. The split is architectural: the operators are protecting their signed delivery layer from revocation events that could burn the stealer track, and vice versa.

May 27, 2026, 00:03 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC36RegionsUS

Four Windows executables carrying a valid Extended Validation code-signing certificate issued to an entity called ORYON TECH LIMITED are circulating as a disguised system-utility package — while a pair of freshly compiled LummaC2 stealers, deliberately stripped of any trusted certificate chain, rides the same delivery infrastructure toward the same targets. The deliberate split is not an oversight.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence