C&CMembers
C&C

PacketStream Installer Trio Shares Expired Cert, Trips GhostSocks Rule

Three PacketStream-branded files — an installer, launcher, and client — carry identical signing timestamps and certificate serials despite distinct import-table hashes, and that certificate lapsed over a year before the files kept circulating. The largest component also fires a YARA rule for the GhostSocks SOCKS-proxy malware family, raising questions about a bundleware chain drifting toward proxy abuse.

Jul 12, 2026, 13:44 (UTC+9)Last seenJul 12, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC21MITRE28

Three binaries carrying the PacketStream brand — an installer, a launcher, and a client — all share one code-signing certificate that expired more than a year before the files were still circulating with it attached. The certificate, issued to "PacketStream Inc" and chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, carries serial number 08 A1 E1 05 55 6E 22 8D 46 FE D7 72 3C 52 19 1E and a signing timestamp of 07:57 AM on May 2, 2024 — identical across all three files…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence