APT
201 stories
APTMembersSep 23, 2026, 14:28 (UTC+9)Russian-Registered AS213010 Has Hosted C2 Since 2019
The most durable artifact in this record isn't a binary or a certificate — it's a network. Autonomous System 213010, registered to an entity RIPE lists as "Gening Nikita Dmitrievich," has hosted at least two IP addresses that anchor domains registered three years apart: 87.251.75.204, which carries a domain first registered on 2023-09-20 (poolfreshstep.com), and 80.66.76.210, which is fronting a domain that was only 14 days old when this record closed (bunnysecurityrelay.com, created…
#VoidArachne#SilverFox#CobaltStrike#AS213010#NICENIC#Cloudflare#piratedsoftwarelure#infrastructurereuseActorsVoid Arachne · Silver FoxIOCf17 · i3 · d4 · u2RegionsBRIndustriesEngineering
APTMembersSep 21, 2026, 06:32 (UTC+9)Cracked-Software Lure Network Runs on Expired EV Cert, Shared Hosting
Three files sitting in the same threat record advertise themselves as ordinary utility software — a network scanner, a product activator, a WhatsApp data-transfer tool — and all three are wrapped in commercial anti-analysis packing strong enough to blunt most of the engines that inspect them. That combination, not the actor label attached to the record, is the actual story here.
#crackedsoftwarelures#codesigningabuse#VMProtectpacking#maliciousdomaininfrastructure#CloudflareDNSpivot#attributionmismatch#AdvancedIPScannerimpersonation#certificaterotationActorsLockbit GangIOCf3 · i0 · d5 · u0MITRE6IndustriesContainers & Packaging
APTPublicSep 20, 2026, 22:41 (UTC+9)Fake Skype Installer Ran a Full Espionage Chain for a Decade
A Win32 executable that calls itself Skype.exe, carries Skype's product name and a "© 2003-2012 Skype and/or Microsoft" copyright string, and still ships completely unsigned has been circulating in low volumes for more than a decade — first submitted for scanning in October 2014, most recently as March 2025. The file (b6ca1211…8f518a403) is flagged by 61 of 78 engines, a strong consensus that has held steady across its long life.
#Molerats#GazaCybergang#AridViper#Skypemasquerade#trojanizedinstaller#anti-analysisevasion#DNSbeacon#espionagemalwareActorsMolerats · Gaza CybergangIOCf1 · i0 · d1 · u1MITRE9RegionsCN · HKIndustriesRetail
APTMembersSep 20, 2026, 14:29 (UTC+9)Fake WebView2 DLL Stalls Sandboxes to Outwait Detection
A DLL calling itself WebView2Loader.dll — the file Microsoft's own browser-embedding runtime uses on tens of millions of Windows machines — turns out to be a 3,544KB Win32 payload that checks for an attached debugger, stalls execution for long stretches, waits for a human to actually touch the keyboard, and probes the BIOS before doing anything else.
#WebView2masquerade#SalatStealer#Vidar#Snowglobe#Varistpacker#sandboxevasion#Let'sEncryptcertificaterotation#retailsectortargetingActorsSnowglobe · Animal FarmIOCf45 · i2 · d1 · u2RegionsUSIndustriesRetail
APTMembersSep 20, 2026, 06:28 (UTC+9)VPN Trojan Trio Shares Revoked EV Signature, Clears Sandbox Despite Flags
Three Windows binaries branded as pieces of a consumer VPN client — a small stub called wire.exe, a much larger DLL called wire.dll, and a standalone installer called upWire.exe — all carry the identical publisher chain: WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained up through GlobalSign GCC R45 EV CodeSigning CA 2020 to GlobalSign's root.
#Cactus#ramnitActorsCactus · Cactus Ransomware GroupIOCf33 · i5 · d9 · u2MITRE20
APTMembersSep 19, 2026, 22:37 (UTC+9)Same Packer, Four Years: Gh0st RAT Toolchain Refuses to Retool
Three Farfli/Gh0st droppers submitted four years apart — one first seen in April 2022, two more that surfaced fresh on September 18, 2026 — carry the identical PEiD packing signature and trip the same Elastic-authored detection logic, a rule called Windows_Trojan_Generic_9e4bb0ce. That kind of toolchain stasis, more than any single new sample, is the story in this cluster: an operator that built a packer wrapper and a Gh0st-derivative payload once and has evidently seen no operational need to…
#SaltySpider#Gh0stRAT#Farfli#rootkitdriver#code-signingcertificateabuse#sandboxevasion#credentialdumping#commandandcontrolinfrastructureActorsSalty Spider · KuKuIOCf14 · i0 · d1 · u3MITRE30RegionsUSIndustriesRetail
APTMembersSep 18, 2026, 23:05 (UTC+9)Aged 2018 Domain Repointed to Fresh Emotet C2 in Turkey
A domain registered back in April 2018 — long enough to have aged out of any registrar-freshness scrutiny — currently resolves to a command-and-control IP that was flagged for the first time on 2026-09-18. The domain is atici.net, and its single A-record points to 185.15.196.157, a Turkish address on AS201520 (Dedicated Telekomunikasyon Teknoloji Hiz. Tic. San. LTD. STI., Istanbul) that carries a Let's Encrypt certificate minted only weeks earlier.
#Emotet#TA542#Excel4macro#command-and-controlinfrastructure#Let'sEncryptcertificates#domainagelaundering#Turkishhosting#retailsectortargetingActorsEmotet Group · TA542IOCf1 · i2 · d3 · u2RegionsUSIndustriesRetail
APTMembersSep 17, 2026, 06:29 (UTC+9)One Blank TLS Certificate Links Four Unrelated Cloud Networks
Thirteen IP addresses spread across a hyperscale social-media company's own network, a discount VPS reseller with points of presence on four continents, and two little-known hosting shells registered in Russia all present the exact same self-signed TLS certificate — serial 1acf3e37b37910d932ea64e6bb27615d6484c07d, with both its issuer and subject fields rendered as the literal string "NONE." That certificate, valid from March 2024 through March 2034, is not the kind of artefact that shows up…
#WireVPN#VPNMaster#codesigningabuse#sandboxevasion#Zenlayer#Bytedanceinfrastructure#self-signedcertificate#commoditymalwaredistributionActorsSpace Pirates · WebwormIOCf70 · i22 · d4 · u0MITRE22
APTMembersSep 16, 2026, 22:43 (UTC+9)Downloader Stacks Three Evasion Tricks, Hides C2 in Alibaba DoH Traffic
A downloader carrying the threat label trojan.sfuzuan/convagent packs three separate anti-analysis tricks into a single unsigned Windows binary — a debugger check, a deliberate stall before execution, and a 32-to-64-bit mode transition known as HeavensGate — and then leans on Alibaba's own DNS-over-HTTPS infrastructure to resolve whatever it talks to next.
#trojan.sfuzuan#convagent#HeavensGate#DNS-over-HTTPS#GoldEvergreen#BusinessClub#DGAdomains#downloaderevasionActorsGold Evergreen · Business ClubIOCf5 · i0 · d7 · u2
APTMembersSep 14, 2026, 22:38 (UTC+9)TA505 Loader Hides Behind Six-Year-Old Mozambique Academic Domain
The most telling artifact in this cluster isn't a binary — it's a URL. rcf.co.mz/mytimeiswriten.exe sits on a domain registered on 2020-05-03 through Mozambique's academic CIUEM Registrar, a domain that still carries active mail routing and a valid SPF record naming its own hosting IP. Rather than spinning up a fresh, throwaway domain that would trip every newly-registered-domain heuristic on the market, whoever is running this operation appears to have repurposed six years of accumulated…
#TA505#Hive0065#rockloader#DuckDNS#Let'sEncryptcertificaterotation#Mozambiquedomainabuse#dynamicDNSC2#bulletproofhostingActorsTA505 · Hive0065IOCf55 · i2 · d1 · u2RegionsDE · ID · IE · ITIndustriesConstruction · Education & Research · Manufacturing
APTMembersSep 12, 2026, 22:27 (UTC+9)APT33-Linked Downloader Wears a Dead Code-Signing Chain
A trojan tracked as bsymem — publicly also known as Donoff — ships with an entire three-tier code-signing chain still attached to the binary: GlassWire, a legitimate desktop network-monitoring vendor, sitting underneath a Symantec Class 3 SHA256 Code Signing CA certificate and a root VeriSign certificate. VirusTotal's verdict on that chain is blunt — "the digital signature of the object did not verify" — and two of the three certificates in it are separately flagged as "not time valid." The…
#APT33#bsymem#Donoff#AutoITdownloader#codesigningabuse#customermgmt.net#sandboxevasion#masqueradingActorsAPT33 · MagnalliumIOCf3 · i0 · d1 · u1MITRE24RegionsCH · JOIndustriesGovernment · Support Services
APTMembersSep 11, 2026, 23:46 (UTC+9)Installer Hides Its Only Flagged File Among Ten Clean Decoys
Ten PNG and CSS files with an identical creation moment sit alongside a single packed Windows executable that carries every detection in the set — a pairing that reads less like a malware family and more like the internals of an ordinary software installer, repurposed. The image assets are unremarkable on inspection: a close button, a hover state, a grey button, a progress bar, a stylesheet named main.css. Individually they register 0/53 to 0/57 across antivirus engines.
#Snowglobe#AnimalFarm#Sig20#babarmalware#trojanizedinstaller#USretailsector#CloudFrontC2#packedexecutableActorsSnowglobe · Animal FarmIOCf18 · i0 · d2 · u0MITRE27RegionsUSIndustriesRetail
APTPublicSep 11, 2026, 22:38 (UTC+9)A Political Decoy Document Reopens a 2016 Word-Processor Flaw
A Korean-language document about inter-Korean political affairs is still being used to trigger a nine-year-old Hangul Word Processor flaw, and the payload it drops is evading a meaningful share of security engines nearly a decade after it was first compiled. The lure — a corrupted HWP container (29430240cb59a12fcde8e4153c0859c90d5a928503a1ca05433f08a7b3c50bf2) carrying an internal object path that resolves to a temp file named for a comparison of "2016 and 2017 South Korea-facing affairs" —…
#Group123#ScarCruft#APT37#ROKRAT#HWPexploit#CVE-2016-2569#SouthKorea#espionageActorsGroup123 · Venus 121IOCf2 · i1 · d0 · u0MITRE21RegionsCH · JOIndustriesSupport Services
APTMembersSep 9, 2026, 22:29 (UTC+9)Pirated Mortal Kombat Installer Feeds Debugger-Aware Loader Chain
Two unsigned Win32 installers dressed up as a pirated "Mortal Kombat 1" setup from the FitGirl repack scene are functioning as the entry point for a debugger-aware loader chain that ends with a second-stage payload fetched over plain HTTP. Both files carry identical product and copyright metadata — "Mortal Kombat 1" and "FitGirl" — and both use the meaningful name setup.exe, with one retaining the full internal path E:\Mortal_Kombat_1_--_fitgirl-repacks.site\setup.exe. Neither is code-signed.
#DBatLoader#DonutLoader#VoidArachne#SilverFox#piratedsoftwarelure#TLScertificatereuse#Russia-hostedinfrastructure#ingresstooltransferActorsVoid Arachne · Silver FoxIOCf9 · i5 · d2 · u1RegionsBR
APTMembersSep 7, 2026, 22:29 (UTC+9)Fake PDF Reader Ecosystem Runs on Two Valid Corporate Code Signatures
Two entirely separate, still-valid commercial code-signing chains are being used in parallel to push the same lure: consumer utility installers — PDF readers, zip tools, photo viewers — that dozens of antivirus engines flag as adware while sandboxes wave them through as clean. Thirteen samples carry a GlobalSign GCC R45 CodeSigning CA 2020 certificate issued to 沧州句号网络科技有限公司 (Cangzhou Juhao Network Technology Co., Ltd.), with detection ratios ranging from 18 to 46 out of roughly 77 engines.
#codesigningabuse#GlobalSigncertificate#DigiCertcertificate#adware#PUPdistribution#ChinaTelecomFujian#Qihoo360impersonation#fakePDFreaderActorsSalty Spider · KuKuIOCf18 · i5 · d0 · u0MITRE10
APTMembersSep 7, 2026, 06:39 (UTC+9)One TLS Certificate Ties Three Alibaba Cloud IPs to Fallback C2
The most concrete signal in this indicator set is not a payload — it is a certificate. Three IP addresses, 163.181.72.193, 163.181.72.200 and 163.181.72.201, all sitting inside the 163.181.72.0/23 block and geolocated to Thailand, present the identical TLS certificate serial 6696262f452fcf46b79266a8 with the identical wildcard subject *.certfallback.com.
#TA505#rockloader#AlibabaCloud#certificatepinning#Thailandinfrastructure#C2fallback#crackedsoftwarelures#TLSfingerprintingActorsTA505 · Hive0065IOCf2 · i5 · d2 · u0IndustriesHealthcare
APTMembersSep 5, 2026, 14:28 (UTC+9)A Shopify Wildcard Certificate Is Serving DarkSide's Command Channel
The freshest piece of this investigation is not the ransomware payload — it is the domain answering for it. baroquetees.com, registered on 2026-02-19 through TUCOWS.COM, CO., resolves to a single IP address, 23.227.38.71, behind Google Cloud DNS name servers (ns-cloud-a1 through ns-cloud-a4.googledomains.com). Its most recently observed TLS certificate, issued by Cloudflare TLS Issuing ECC CA 1, does not carry baroquetees.com in its subject or SAN fields at all.
#DarkSideransomware#GoldWaterfall#TLScertificatemismatch#Cloudflareinfrastructure#command-and-controldomain#Shopifywildcardcertificate#Romania#IDSsignaturedetectionActorsDarkside · Gold WaterfallIOCf1 · i0 · d1 · u2MITRE35RegionsRO
APTMembersSep 5, 2026, 06:28 (UTC+9)A 2019 Emotet Invoice Lure Resurfaces With Newly Certified Dormant Domains
A Word document dressed as a German electricity invoice and a Polish payment notice has resurfaced in telemetry alongside four domains whose registration dates read like a timeline of the internet itself — 1997, 2004, 2014, and 2026. Three of those domains sat dormant for a decade or more before anyone bothered to issue them a fresh TLS certificate; the fourth, registered this year, doesn't even carry its own certificate, borrowing a wildcard from a shared hosting platform instead.
#Emotet#TA542#MummySpider#malspam#domainreactivation#TLScertificateabuse#defenseevasion#invoicephishinglureActorsEmotet Group · TA542IOCf3 · i0 · d4 · u7RegionsDE
APTMembersSep 4, 2026, 14:35 (UTC+9)Pirated Windows Activator Hides Five-Stage Intrusion Kit
A "free" copy of KMSAuto — the activation utility that generations of users have downloaded to skirt Windows licensing — carries a code-signing certificate that the distributor minted for itself, a loader dressed as a Google Chrome updater, a userland rootkit, a coin-mining payload, and a fifteen-year-old kernel driver still on the LOLDrivers vulnerable-driver list. None of those five components is individually novel.
#KMSAuto#APT27#BYOVD#WinRing0#code-signingabuse#coinminer#rootkit#MalaysiagovernmentsectorActorsAPT27 · TEMP.HippoIOCf17 · i0 · d3 · u1MITRE58RegionsMYIndustriesGovernment
APTMembersSep 3, 2026, 22:28 (UTC+9)Decade-Old Flash Exploit Rides Along With Game-Trainer Loader
A Vietnamese-language "auto-trainer" toolkit for the online game Vo Lam Truyen Ky is quietly bundling something considerably nastier than a speed-hack: a packed loader called VulanPK.exe paired, byte for byte in the same build directory, with an exploit DLL that still carries the fingerprint of a 2015 Adobe Flash Player vulnerability.
#BlueBottle#Opera1er#CVE-2015-2387#game-trainermalware#Vietnam#MegaDNS#Taggantpacker#malvertisingActorsBlueBottle · Opera1erIOCf80 · i1 · d2 · u3MITRE35RegionsAT
APTMembersAug 31, 2026, 14:42 (UTC+9)Five DDNS Hostnames, One Backend, Tied to DarkHotel Downloader
Five command-and-control hostnames spread across four unrelated free dynamic-DNS providers — Zyns, Crabdance (used twice), ServeHTTP, and Mooo — all resolve to the identical backend panel path, `/bin/home/home.php and /bin/home/view.php, and all carry the same encoded parameter string, a2=1ae8bdddea716a1fa3c8492572357e80. That repetition is the news here: gigamiros.zyns.com, microzion.crabdance.com, mirosmial.crabdance.com, microgenuinsman.servehttp.com and nanobis.mooo.com look, on the…
#DarkHotel#garveep#dynamicDNSabuse#downloadermalware#espionage#HongKong#Japan#technologysectorActorsDarkHotel · Fallout TeamIOCf1 · i1 · d1 · u25MITRE8RegionsHK · JPIndustriesTechnology
APTMembersAug 29, 2026, 22:36 (UTC+9)A Builder Fingerprint Ties Three 'Different' Trojans to One Assembly Line
Three files carrying three unrelated threat labels — trojan.msil/jalapeno, trojan.msil/agenttesla and trojan.msil/zusy — turn out, on inspection of their import tables, to be the same product line. Each one carries the identical import hash f34d5f2d4577ed6d9ceec516c1f5a744, a fingerprint of the exact function-import list a .NET builder or crypter service stamps into every executable it produces.
#imphash#MSILtrojan#AgentTesla#GCleaner#pay-per-installloader#Cloudflareinfrastructure#commoditystealer#OperationBlackAtlasActorsOperation Black AtlasIOCf23 · i2 · d5 · u7MITRE51
APTMembersAug 28, 2026, 23:11 (UTC+9)Signed Bright Data Component Escalates From Trojan to Stealer
A binary called net_updater.exe, carrying a valid, unrevoked Authenticode chain issued to Bright Data Ltd through DigiCert's Trusted G4 code-signing program, has moved through three successive builds between September 2025 and June 2026 — and detection engines have not agreed on what to call it at any point along the way. The first build, submitted in September 2025 (ae182434d7a588ed1d73054394fca0d95d8ea8d1b2cdb51477351e7c1df0932d), drew the label trojan.luminati/brightdata from 21 of 76…
#BrightData#PBotstealer#codesigningabuse#adware#trojan#Cactusransomwaregroup#TLScertificatereuse#domaininfrastructureActorsCactus · Cactus Ransomware GroupIOCf14 · i14 · d20 · u4MITRE8IndustriesHealthcare · Telecommunications
APTMembersAug 28, 2026, 22:31 (UTC+9)Disposable Storefronts Share One DNS Backbone Behind GCleaner Loaders
Three domains dressed up as e-commerce storefronts — shhsift.click, kupzovo.shop, and vexdico.shop — resolve through the identical nameserver pair ns1.dyna-ns.net and ns2.dyna-ns.net, the Dynadot-operated DNS infrastructure that sits behind all three registrations. That is not three operators independently choosing the same registrar; it is the same DNS footprint appearing on domains with unrelated naming conventions and different final IP addresses (159.65.136.5, 66.228.41.52, and…
#GCleanerloader#InjectorNett#APT28misattribution#Dynadotinfrastructure#Let'sEncryptYE2#pay-per-install#commoditymalware#disposabledomainsActorsAPT28 · StrontiumIOCf15 · i1 · d5 · u9MITRE23
APTMembersAug 28, 2026, 14:29 (UTC+9)Fake uTorrent Wildcard Certificate Traces to Iceland Hosting Pair
Two servers sitting on the same /19 block in Reykjavík are presenting an identical TLS certificate for a wildcard subject that has nothing to do with the network that hosts them: `.utorrent.com. The IPs — 82.221.103.245 and 82.221.103.246 — both belong to AS50613, Advania Island ehf, and both serve a GoDaddy-issued certificate carrying serial number 33902efffb1704a7, with the subject alternative names .utorrent.com and utorrent.com.
#Turla#Sality#uTorrentimpersonation#certificateabuse#AdvaniaIsland#Icelandhosting#fileinfector#retailsectorespionageActorsTurla · Iron HunterIOCf27 · i3 · d1 · u0MITRE59RegionsUSIndustriesRetail
APTMembersAug 25, 2026, 22:29 (UTC+9)Fake Flash Installer Hides PlugX Loader With Timer-Based Sandbox Checks
A dropper calling itself install_flash_player.bin does something a real Adobe installer never does: it reads the CPU timer directly to work out whether it is being watched, checks for an attached debugger, and then simply waits — sometimes for long stretches — before it does anything else. Only after that stall completes does the Nullsoft-packaged installer (c56ac01b…) begin dropping its real payload.
#MustangPanda#PlugX#Korplug#CobaltStrike#sandboxevasion#NSISinstaller#Switzerland#supportservicessectorActorsMustang Panda · HoneyMyteIOCf3 · i0 · d2 · u81MITRE20RegionsCHIndustriesSupport Services
APTMembersAug 25, 2026, 14:37 (UTC+9)Four Chinese Shell Firms, One DigiCert Chain, One Hidden RAT
Twenty Chinese-language "PC optimizer" and wallpaper-app binaries in this catalog carry code-signing certificates from four different corporate entities — 成都奇鲁科技有限公司, 北京创想界科技有限公司, 成都盈畅时代文化传播有限公司, and 成都赤侠信息科技有限公司 — and every single one of those certificates chains to the identical issuing authority, "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1." That is not four vendors independently buying trust from the same certificate authority; the detection spread inside each cohort argues…
#codesigningabuse#certificaterotation#Ludashi#PolarWind#PubNubRAT#ChinaMobileAS56047#PUAadware#DigiCerttrustchainActorsFIN6 · Skeleton SpiderIOCf36 · i4 · d1 · u5MITRE28
APTMembersAug 23, 2026, 14:27 (UTC+9)One Static Token Ties Four Rotating DarkHotel C2 Domains Together
An unsigned 2.4MB Windows executable masquerading as an Adobe updater (catalogued as 672c82c1…d26b65ef, and referred to here as the Catch.exe downloader after its internal name) carries a full anti-analysis stack — virtualization and sandbox checks [T1497, T1497.002, T1497.003], debugger evasion [T1622], and code injection into another process's window memory [T1055.011] — before it ever reaches out to command infrastructure.
#DarkHotel#dynamicDNS#C2infrastructure#downloadermalware#anti-analysistechniques#Japantelecomtargeting#codesigningevasion#APT-C-06ActorsDarkHotel · Fallout TeamIOCf1 · i0 · d1 · u19MITRE10RegionsJPIndustriesTelecommunications
APTMembersAug 22, 2026, 22:37 (UTC+9)Decade-Old Sality Worm Feeds a Modern XMRig Cryptomining Chain
The oldest file in a cluster CTX Team pulled together this week first surfaced in 2010 — a self-propagating Sality-family dropper that still spreads over USB autorun and waits for a user to double-click it before running. Fifteen years later, the same intake batch contains a modern XMRig-derived cryptomining binary carrying nine named YARA detections and a dormancy routine that checks the CPU clock before it starts hijacking a victim's processor.
#Salityworm#SaltySpider#XMRigcryptomining#Tofseebotnet#USBautorunpropagation#self-signedcertificate#sandboxevasion#retailsectortargetingActorsSalty Spider · KuKuIOCf16 · i0 · d5 · u34MITRE15RegionsUSIndustriesRetail
APTMembersAug 22, 2026, 14:30 (UTC+9)Signed 'PC Cleaner' DLLs Flagged as PubNubRAT by Sandbox Engine
A system-optimizer bundle marketed under the WinOptimize brand carries two DLLs that a dedicated malware sandbox names as a remote-access trojan called "PubNubRAT" — even though both files are digitally signed and roughly two-thirds of static antivirus engines wave them through as ordinary adware. The privacy.dll component (82c06ae2…f0928) triggers a malicious verdict from the C2AE sandbox, which classifies it outright as a RAT and names PubNubRAT as the payload family; a second DLL from the…
#PubNubRAT#WinOptimize#Ludashiadware#code-signingabuse#ChinaMobileAS56047#sandboxevasion#TA428/ThunderCats#PUA-to-RATpivotActorsTA428 · ThunderCatsIOCf17 · i7 · d2 · u13MITRE24
APTMembersAug 21, 2026, 22:58 (UTC+9)Three Unrelated Trojans Hit in 48 Hours, One Fake Mail Server Behind Them
Between August 10 and August 11, 2026, three completely unrelated pieces of commodity malware surfaced in rapid succession — a JavaScript downloader carrying an Agent Tesla/Etecer label, a RAR-packaged ModiLoader dropper, and a heavily obfuscated JavaScript file tagged Luainj — none of them sharing an import hash, a code signer, or even a threat family name with the others.
#TA505#AgentTesla#ModiLoader#Luainj#trimnt.com#phishinglure#commoditymalware#C2infrastructureActorsTA505 · Hive0065IOCf5 · i1 · d1 · u0RegionsAU · CH · DE · ESIndustriesBusiness Associations · Chemicals · Education & Research
APTMembersAug 19, 2026, 14:40 (UTC+9)Lazarus-Tagged Feed's Only Real Evidence Is a MyDoom-Era Worm
A Windows binary classified as worm.mydoom/emailworm (fdeacb79…) — flagged by 66 of 76 engines and carrying the popular names "mydoom," "emailworm," and "amfu" — is the only file in this record that comes with any forensic detail at all. Of 33 catalogued file hashes tied to the package, 32 are bare values: no type, no size, no detection count, nothing.
#LazarusGroup#MyDoom#emailworm#malwareattribution#threatintelligencefeeds#CDNinfrastructure#falseattribution#dataqualityActorsLazarus Group · Hastati GroupIOCf33 · i10 · d11 · u0RegionsDE
APTMembersAug 19, 2026, 06:34 (UTC+9)One EV Certificate Signs Four Files, Fools Every Sandbox
Four separate binaries — a loader, an updater, a secondary installer, and an MSI payload — all carry the identical Sectigo EV code-signing chain issued to "ORYON TECH LIMITED," and that shared, currently valid certificate is functioning as an active evasion layer rather than a simple trust marker. Static antivirus engines are not fooled: 24 to 44 of roughly 75 to 76 engines flag each file as malicious.
#ORYONTECHLIMITED#EVcode-signingabuse#adwareinstallerchain#microleaves/legionPUPfamily#crackedsoftwarelure#sandboxevasion#domaininfrastructurereuse#pay-per-installActorsPatchwork · ChinastratsIOCf21 · i0 · d6 · u14MITRE49RegionsIN
APTMembersAug 17, 2026, 22:29 (UTC+9)Same Evasion Trick, Same Compiler Run, Tie Five Files Together
Three files in this cluster carry three different VirusTotal threat labels — a clipboard-hijacking banker, a generic dropper, and a DLL flagged for lateral spread — yet all three share the identical pair of behavioural tags: a check for whether a debugger is attached, and a routine that stalls for long periods before doing anything else. That repetition, sitting underneath payloads that otherwise look unrelated, is the more interesting story here than any single malware family.
#APT28#ClipBanker#PowerLoader#sandboxevasion#anti-debugging#CloudFlareOriginCertificate#AS214351#commoditycrimewareActorsAPT28 · StrontiumIOCf54 · i3 · d4 · u4MITRE66RegionsJO · NL · RO · SA
APTMembersAug 16, 2026, 22:28 (UTC+9)Shared Self-Signed TLS Cert Links Bytedance, Zenlayer IPs to VPN Trojans
Four IP addresses that share nothing else in common are running the identical self-signed TLS certificate — two sitting inside Bytedance's US-registered network block, two inside Zenlayer's Philippines allocation on the other side of the Pacific. The certificate carries serial number 1acf3e37b37910d932ea64e6bb27615d6484c07d, with both issuer and subject fields recorded simply as "NONE," and it is valid from March 12, 2024 clear through March 10, 2034 — a ten-year span that is itself unusual for…
#UAC-0063#TAG-110#WireVPN#PBotstealer#BrightDataimpersonation#self-signedcertificate#code-signingabuse#VPNPUAActorsUAC-0063 · TAG-110IOCf36 · i4 · d1 · u0MITRE21
APTMembersAug 16, 2026, 14:29 (UTC+9)Fake VPN Installers Keep Shipping Under Revoked Signing Certificates
Two trojanized VPN and proxy installer families have kept circulating for months after the code-signing certificates behind them were marked revoked or no longer time-valid — a pattern that turns a routine trust-chain failure into an operational feature rather than a bug. One cluster, branded WireVPN, rides a GlobalSign EV certificate issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED; the other, a fake VPN suite calling itself VPNMaster, rides a single DigiCert certificate issued to INNOVATIVE…
#WireVPN#VPNMaster#codesigningabuse#WEILAINETWORKTECHNOLOGY#INNOVATIVECONNECTINGPTE#PEGTECHINC#sandboxevasion#trojanizedVPNinstallersActorsAPT15 · ROYALAPTIOCf17 · i3 · d8 · u2MITRE8IndustriesFood & Beverages
APTMembersAug 15, 2026, 22:30 (UTC+9)Chinese Adware Chain Hides RAT Behind UnionPay-Spoofing TLS Certs
Ten of eleven IP addresses tied to a Chinese adware delivery cluster CTX Team has been mapping sit inside a single autonomous system — AS4837, CHINA UNICOM China169 Backbone — and seven of those ten present an identical .unionpayintl.com wildcard TLS certificate that has nothing to do with UnionPay International's actual payment infrastructure.
#ChinaUnicomAS4837#PubNubRAT#codesigningabuse#TLScertificateimpersonation#UnionPayspoofing#adwaresupplychain#LuDaShiPolarWind#FIN6misattributionActorsFIN6 · Skeleton SpiderIOCf45 · i11 · d3 · u0MITRE14
APTMembersAug 15, 2026, 06:31 (UTC+9)Pirated CCleaner Crack Stalls, Then Digs In For Persistence
A Windows executable disguised as an activation crack for pirated software spends its first minutes on a victim machine doing nothing that looks like an attack at all — reading the CPU timer, checking installed memory, polling the BIOS and USB bus, watching for a debugger. Only once those checks come back clean does it write itself somewhere that survives a reboot.
#AgentTesla#Negasteal#crackedsoftwarelure#anti-sandboxevasion#Cloudflareinfrastructure#pay-per-installloader#Patchwork#APT28ActorsPatchwork · ChinastratsIOCf6 · i0 · d4 · u15MITRE29RegionsAD · AU · BG · BSIndustriesConstruction · Education & Research · Government
APTMembersAug 14, 2026, 14:45 (UTC+9)Fake Payment-Receipt RAR Hides JS Downloader for AgentTesla
A Spanish-language RAR attachment titled "Detalles de los recibos de pago" — payment receipt details — carries a single embedded JavaScript file that a sandbox platform ultimately traces to AgentTesla-class credential theft. What makes this cluster worth a second look is not the lure itself, which is unremarkable, but the mismatch in how security engines treat its two stages: the RAR container is flagged by 13 of 76 engines, while the JavaScript it unpacks into is flagged by 31 of 76 — nearly…
#AgentTesla#ModiLoader#SLoad#TA505#Hive0065#phishing#credentialtheft#NamecheapinfrastructureActorsTA505 · Hive0065IOCf3 · i1 · d1 · u1RegionsAT · CY · DE · EGIndustriesAutomotive · Retail · Support Services
APTMembersAug 13, 2026, 00:05 (UTC+9)Shared Certificate Serial Ties Four Lookalike Domains to One Brazil IP
Four freshly registered domains — zelpx.garden, carogra.biz, tzpx.courses, and fightwa.biz — resolve through the identical authoritative nameserver pair ns1.dyna-ns.net and ns2.dyna-ns.net, despite having been registered across two separate windows nearly three months apart. That single fact, verifiable directly against the WHOIS and DNS records, is the strongest thread running through this indicator set, and it is considerably more solid than anything the accompanying file collection offers.
#Dynadot#Hostinger#Let'sEncryptcertificatespoofing#domainmasquerading#APT28attribution#stealerlogs#Exoduswallet#BrazilhostinginfrastructureActorsAPT28 · StrontiumIOCf32 · i1 · d4 · u4MITRE34RegionsAR · CL · CM · EEIndustriesFood & Beverages
APTMembersAug 12, 2026, 06:37 (UTC+9)A 2020 Loader Stub Still Circulates in Fresh Detections Today
Twenty file indicators tied to Ramsay- and DarkHotel-labeled trojans converge on a single, unmodified compiled artifact: an import-table fingerprint of 34791a1ad0a42b816d48d1d1c182fe7d and a Rich PE header hash of d9068e3808ee41e8c6f32c9fd4e83a79, both frozen to a compile timestamp of 2020-03-04. That exact build keeps resurfacing under new detections as late as December 2025 — five years after it was compiled — wearing four different VirusTotal threat labels along the way.
#DarkHotel#Ramsaytrojan#UACMeUACbypass#reflectiveDLLinjection#imphashreuse#gamelauncherlure#SerbianresidentialIP#espionagemalwareActorsDarkHotel · Fallout TeamIOCf20 · i1 · d0 · u0MITRE11RegionsPHIndustriesTechnology
APTMembersAug 11, 2026, 14:28 (UTC+9)QuasarRAT Toolkit Recompiled for 13 Years Gains a Crypto Clipper
Four newly-flagged Windows binaries tied to a cluster the upstream feed labels LazyScripter share an unbroken thread: the same QuasarRAT-derived toolkit fingerprint, first compiled in 2011 and still shipping in September 2024, with a clipboard-hijacking wallet-swap module now bolted onto the frame. Rather than a fresh malware family, what CTX Team's review of the sample set shows is a chassis — Quasar's remote-access core, wrapped in RDP-wrapper persistence and Vermin/xRAT keylogging code —…
#LazyScripter#QuasarRAT#VenomRAT#xRAT#VerminKeylogger#cryptocurrencyclipper#portmap.iotunneling#RDPWrapperpersistenceActorsLazyScripterIOCf9 · i1 · d1 · u2MITRE30RegionsPT
APTMembersAug 11, 2026, 07:30 (UTC+9)One Certificate, Five Servers, Two ASNs: A Fallback C2 Fingerprint
Five IP addresses scattered across Indonesia, the Philippines, Vietnam, and Malaysia are all answering HTTPS requests with a certificate naming the same subject: *.certfallback.com. That alone would be a modest coincidence — shared wildcard certificates get resold and reused constantly in commodity hosting. What turns it into a diagnostic fingerprint is that four of those five hosts — 128.1.178.192 (Indonesia), 128.1.45.175 (Vietnam), 43.109.107.28 (Malaysia) and 155.102.33.22 (Malaysia) — are…
#certfallback.com#PureLogStealer#DustSquad#APT-C-34#offercorebundler#EVcodesigningabuse#SoutheastAsiainfrastructure#GlobalSigncertificatereuseActorsDustSquad · APTC34IOCf3 · i5 · d1 · u1MITRE5IndustriesTechnology
APTMembersAug 10, 2026, 06:35 (UTC+9)A Decade-Old Adware Builder Wearing an Espionage Label
Four JavaScript files sitting inside a record tagged "apts" and attributed to APT39 turn out, on inspection of their own build fingerprints, to be the same payload repackaged under at least six different Chrome extension identities — a mass-cloning technique straight out of the Crossrider adware playbook, not a nation-state implant.
#APT39#Chafer#Crossrider#adware#browserextensions#Chromeextensions#PUA#threatintelligenceattributionActorsAPT39 · ChaferIOCf20 · i0 · d1 · u3RegionsGB
APTMembersAug 9, 2026, 20:14 (UTC+9)Same Softonic Cert Signs a RustDesk Impostor and a Near-Clean Twin
A Win32 installer signed with the identical Softonic International SA code-signing certificate turns up in two forms with wildly different fortunes: one build draws 31 of 76 antivirus detections and ships under aliases that impersonate RustDesk and Lenovo Vantage, while its cert-mate scores a near-clean 4 of 76 and drew almost no submissions at all.
#RustDeskimpersonation#LenovoVantageimpersonation#Softoniccertificateabuse#code-signingcertificatereuse#adwarebundling#sandboxevasion#CloudFrontinfrastructure#SaltySpiderActorsSalty Spider · KuKuIOCf2 · i0 · d1 · u2MITRE21RegionsAR · BO · BR · CLIndustriesAgriculture · Construction · Education & Research
APTMembersAug 9, 2026, 10:45 (UTC+9)Old RemCom Hacktool Masks a Clean-Scoring WinSW Impostor
A remote-command-execution hacktool compiled on 2012-08-09 is still being resubmitted under randomized filenames as recently as July 2026, flagged by 46 of 75 engines and matched by three named YARA rules — and sitting in the same indicator set is a 16.8-megabyte binary posing as the open-source WinSW Windows Service Wrapper that clears every one of 77 antivirus engines outright.
#RemCom#WinSWimpersonation#lateralmovement#bulletproofhosting#Proton66#Flyservers#njRAT#CactusransomwaregroupActorsCactus · Cactus Ransomware GroupIOCf2 · i13 · d0 · u0MITRE20
APTMembersAug 9, 2026, 01:46 (UTC+9)A Disposable AWS Front and a CDN Wildcard Are the Real Story, Not the File
Two pieces of infrastructure — a beacon domain delegated through Amazon's own nameservers and a CDN-fronted IP wearing someone else's wildcard certificate — carry far more evidential weight in this record than the single file attached to it. The domain, wb.sleevesbarbing.com, resolves through eight rotating A-records behind AWS Route53 delegation and serves six URLs that all follow the identical templated path /mtn/130079/<32-character-hash>.<epoch-timestamp>.000.
#AWSRoute53delegation#CDNwildcardcertificate#AdvancedIPScanner#Famatechcodesigning#Edgenextinfrastructure#telecomsectortargeting#disposableC2domain#expiredcertificatechainActorsLockbit GangIOCf1 · i1 · d1 · u6MITRE4IndustriesTelecommunications
APTMembersAug 8, 2026, 23:04 (UTC+9)Windows Defender-Killer Tool Folded Into XRed RAT Dropper
A commodity tool built to switch off Windows Defender with one click has turned up inside the build of a remote-access-trojan dropper — not dropped alongside it, but sharing the same crowdsourced YARA signature. The standalone hacktool, tracked publicly as DefenderControl and carried in this set as 1ef6c1a4dfdc39b63bfe650ca81ab89510de6c0d3d7c608ac5be80033e559326, and a Synaptics-driver-themed dropper that sandboxing names as the XRed RAT,…
#GorgonGroup#Subaat#XRedRAT#DefenderControl#HongKongtechnologysector#dynamicDNSabuse#masqueradetechnique#espionageActorsGorgon Group · SubaatIOCf15 · i1 · d0 · u0MITRE29RegionsHKIndustriesTechnology
APTMembersAug 8, 2026, 19:30 (UTC+9)Valid Code Signatures Mask PBot Stealer in VPN/Proxy Installers
A Windows installer branded as Bright Data's residential-proxy SDK carries a complete, unbroken DigiCert code-signing chain — and still returns a sandbox verdict naming the PBot stealer classification. Across ten files reviewed by CTX Team, three separate code-signing identities — Bright Data Ltd, WEILAI NETWORK TECHNOLOGY CO., LIMITED, and INNOVATIVE CONNECTING PTE.
#PBotstealer#code-signingabuse#proxyware#BrightData/Luminati#WireVPN#VPNMaster#DigiCert#PUAActorsEmotet Group · TA542IOCf15 · i36 · d51 · u10MITRE22
APTMembersAug 7, 2026, 06:05 (UTC+9)Old Macro-to-PowerShell Emotet Chain Still Fools Every Sandbox
A macro-laced Word document circulating against United States education and research targets is producing a rare thing in modern detection telemetry: unanimous agreement. All three sandboxes that processed the sample — C2AE, ReaQta-Hive, and BitDam ATP — return a "malicious" verdict, and 43 of 75 antivirus engines flag the file outright.
#Emotet#TA542#macromalware#PowerShelldownloader#educationsector#masquerading#Let'sEncryptcertificates#loader-for-hireActorsEmotet Group · TA542IOCf3 · i1 · d2 · u5RegionsUSIndustriesEducation & Research