APTMembers
APT

Expired-Cert Installer Evades Sandboxes, Feeds 15-Domain Crypto Fraud Net

A 4.3 MB Windows installer impersonating popular freeware uses a five-technique anti-sandbox suite and an expired Sectigo code-signing certificate to slip past automated defences. Once clear, it routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains toward credential harvesting and crypto fraud.

May 27, 2026, 05:51 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC94MITRE12

A 4.3-megabyte Windows installer, dressed in the branding of legitimate freeware and carrying a Sectigo-issued code-signing certificate that had already expired, is the entry point for a financially motivated campaign that routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence