APTMembers
APT

Spring Dragon Hides GCleaner in VR Installer With 4-Year-Old Certificate

A dropper impersonating an HTC VIVE Software installer carries a DigiCert code-signing certificate that expired in April 2021, more than four years before the file surfaced. The payload beacons to three .cfd command-and-control domains registered, TLS-provisioned, and Cloudflare-proxied within a single 72-hour window. CTX Team links the campaign to Spring Dragon, a China-aligned APT actor with an espionage mandate.

Jun 19, 2026, 03:56 (UTC+9)Last seenJun 19, 2026Severity77ByCTX TeamActorSpring DragonLotus BlossomIOC10MITRE12

A Windows executable posing as an HTC VIVE Software installer has surfaced carrying a DigiCert code-signing certificate that expired in April 2021 — more than four years before the file appeared on any scanner — while beaconing to a trio of command-and-control domains registered, TLS-provisioned, and Cloudflare-proxied within a single 72-hour window.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence