
Spring Dragon Hides GCleaner in VR Installer With 4-Year-Old Certificate
A dropper impersonating an HTC VIVE Software installer carries a DigiCert code-signing certificate that expired in April 2021, more than four years before the file surfaced. The payload beacons to three .cfd command-and-control domains registered, TLS-provisioned, and Cloudflare-proxied within a single 72-hour window. CTX Team links the campaign to Spring Dragon, a China-aligned APT actor with an espionage mandate.
A Windows executable posing as an HTC VIVE Software installer has surfaced carrying a DigiCert code-signing certificate that expired in April 2021 — more than four years before the file appeared on any scanner — while beaconing to a trio of command-and-control domains registered, TLS-provisioned, and Cloudflare-proxied within a single 72-hour window.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read