APT
175 stories
APTMembersJul 18, 2026, 13:35 (UTC+9)Proxyware Family Resigned Four Times to Dodge Detection
A ninety-file cluster now under review shows a builder rebuilding and re-signing the same proxyware binary at least four times between July 2025 and March 2026, watching its own detection ratio slide from 22 out of 75 engines down to 8 out of 76 as each new build shipped. The four samples — carrying the meaningful name net_updater.exe and the internal product tag "Bright SDK" — share a single import-table hash, a4383347bad6319cb6d1cefa3c6272d8, and near-identical vhash fingerprints, yet each…
#BrightData#codesigningabuse#proxyware#PBotstealer#WireVpnPc#certificaterotation#VPNtrojan#attributionmismatchActorsCactus · Cactus Ransomware GroupIOCf89 · i14 · d36 · u8MITRE17
APTMembersJul 17, 2026, 05:32 (UTC+9)Valid NordVPN Certificate Masks Signed Dropper, Zero AV Hits
A single Win32 executable sits at the center of this campaign, and its most interesting property is not what it does but what it is trusted to do. The file carries a fully valid GlobalSign EV code-signing chain — "nordvpn s.a.," chained through GlobalSign GCC R45 EV CodeSigning CA 2020 up to GlobalSign Root CA - R3 — with a signing date of July 13, 2026 and a product string reading "NordVPN," version 8.7.2.0. Every certificate in that chain shows a "Valid" status.
#code-signingabuse#GlobalSignEVcertificate#Proton66#NordVPNmasquerade#CommentCrew#APT1#CDNimpersonation#engineeringsectorespionageActorsComment Crew · Byzantine CandorIOCf1 · i4 · d1 · u6MITRE5IndustriesEngineering
APTMembersJul 15, 2026, 21:37 (UTC+9)KMSpico Crack Kit Adds Cryptominer, Clipper on Same Old Rail
The latest sweep of Salty Spider's long-running KMSpico/AutoKMS distribution cluster turned up 19 new file hashes and four new URL variants — and not a single new IP address or domain. That lopsided delta is itself the story: the operators behind this pirated-Windows-activation funnel have left their hosting fabric completely untouched while quietly expanding what the funnel actually delivers.
#SaltySpider#KMSpico#AutoKMS#XMRig#clippermalware#cryptojacking#ZettaHostingSolutions#softwarepiracyActorsSalty Spider · KuKuIOCf33 · i3 · d4 · u33MITRE12IndustriesHealthcare
APTMembersJul 15, 2026, 13:37 (UTC+9)Six-Year-Old Domain, Faked Autodiscover Cert Outshine Blank File Hashes
Three subdomains carved out of a Thai medical-software vendor's own domain zone, a Singapore-hosted IP wearing a certificate that borrows another hosting provider's name, and a six-year-old Chinese-registered domain freshly reissued with a GoDaddy certificate — together these form the only legible signal in a record that otherwise offers almost nothing.
#bmscloud.in.thcluster#A2Hostingcertificatemasquerade#xsbl.netdomainreuse#APT28#DonotTeam#APT15Ke3chang#healthcaresectortargeting#TLScertificateabuseActorsAPT28 · StrontiumIOCf16 · i3 · d4 · u0MITRE29IndustriesGovernment · Healthcare · Telecommunications
APTMembersJul 14, 2026, 22:23 (UTC+9)25-Year-Old Domain Shares Name Servers With Fresh Emotet Asset
Two domains registered nearly a quarter-century apart are pointed at an identical set of authoritative name servers — a provisioning fingerprint that says more about this campaign's operators than any single payload does. quasi-monkey.com, registered through Porkbun LLC on 2000-09-11 and sitting on the internet for more than 9,400 days, and andysresume.info, registered on 2025-02-03, both delegate to the same four Porkbun infrastructure hosts: curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com,…
#Emotet#TA542#nameserverdelegation#Let'sEncryptcertificateabuse#IBANphishinglure#macrodownloader#infrastructurefingerprinting#financesectortargetingActorsEmotet Group · TA542IOCf3 · i2 · d3 · u4RegionsDEIndustriesTechnology
APTMembersJul 14, 2026, 14:11 (UTC+9)17 IPs, Three Budget Hosts, No Hardened C2 Behind KMS Lure
The indicator set built around a pirated Windows-activation script doesn't resolve into a single hardened command post — it resolves into three separate landlords. Cross-referencing the 17 IP addresses tied to this record turns up three matched pairs, each pair sitting on the identical autonomous system: 195.3.220.103 and 109.205.211.94 both answer from AS201814, registered to MEVSPACE sp.
#APT40#Gozi#KMSactivatorlure#sandboxevasion#VPSinfrastructure#certificatemisconfiguration#trojan.powershell/abtrojan#threatattributionActorsAPT40 · MudcarpIOCf1 · i17 · d0 · u0MITRE4IndustriesTechnology
APTMembersJul 14, 2026, 13:34 (UTC+9)Two Adware Families Share One GlobalSign EV Cert Chain
Two commodity adware installers with nothing else in common — different file types, different packers, different threat labels, submitted sixteen months apart — chain to the exact same GlobalSign intermediate certificate. That single overlap, buried inside a feed-tagged "APT28" cluster, turns out to be the most concrete, independently verifiable signal in the entire dataset, and it has nothing to do with espionage tradecraft.
#APT28misattribution#adware#MediaArena#ByteMediaBrowserAssistant#EVcodesigningcertificate#GlobalSign#redirectgateinfrastructure#PUPmonetizationActorsAPT28 · StrontiumIOCf13 · i0 · d6 · u6MITRE24IndustriesNon-Profit
APTMembersJul 12, 2026, 21:35 (UTC+9)APT15-Linked Set Shows Three-Tier, Cert-Rotated Hosting Discipline
Four subdomains — meddup.bmscloud.in.th, api.notify.bmscloud.in.th, donorcheck.bmscloud.in.th, and moph-phr.bmscloud.in.th — all live inside the same legitimate-looking DNS zone, bmscloud.in.th, registered through the Thai registrar THNIC to Bangkok Medical Software Co., Ltd. Three of the four resolve to the identical IP, 171.103.78.30, and the cohort as a whole shares one registrar across all four names — the kind of single-administrative-point pattern that tells an analyst these are…
#APT15#Ke3chang#Mirage#healthcaretargeting#governmenttargeting#Thailand#TLSinfrastructure#certificaterotationActorsAPT15 · ROYALAPTIOCf9 · i3 · d10 · u1MITRE9IndustriesGovernment · Healthcare · Telecommunications
APTMembersJul 12, 2026, 13:35 (UTC+9)Seven Fake FIFA Job Portals Share One Registrar, One Certificate
Seven lookalike domains built around FIFA hiring and career themes — fifa-careerhub.com, fifa-hr.com, jobs-fifa.com, fifa-careerpath.com, fifa-hiring.com, fifa-careerportal.com, and fifahiring.com — sit behind a single automated registration pipeline. Six of the seven were registered through Name.com, Inc., resolve to the identical A-record 91.195.240.94, share all four name.com nameservers (ns1kpv, ns2kry, ns3jmt, ns4dmx), and were issued near-identical certificates from DigiCert's "Encryption…
#TA505#FIFArecruitmentphishing#VBScriptdownloader#domainfactory#OmegatechLTD#AS202412#DigiCertcertificateabuse#bulletproofhostingActorsTA505 · Hive0065IOCf48 · i5 · d8 · u2MITRE17
APTMembersJul 11, 2026, 22:06 (UTC+9)Old and New Certificates Both Fool Antivirus in Same Cluster
A 2012-era remote-access tool still clears the majority of antivirus engines on the strength of a VeriSign signature that has technically expired but still chains to a valid root — while, on the other end of the trust spectrum, a binary carrying a fully current DigiCert code-signing chain issued this March slips past most detection under a stealer classification.
#code-signingabuse#FlawedAmmyy#PBotstealer#BrightData#SaltySpider#CDN-frontedC2#certificatetrust#T1553.002ActorsSalty Spider · KuKuIOCf26 · i3 · d8 · u0MITRE13IndustriesConstruction · Containers & Packaging · Education & Research
APTMembersJul 11, 2026, 05:33 (UTC+9)Expired Certificate, Still Trusted: A Bundler Wearing Four Disguises
A single Win32 binary circulating under the guise of at least four unrelated software titles — Resource Hacker, the XMEye video-surveillance client, the KeyTweak keyboard remapper, and the log viewer glogg — carries a code-signing chain that keeps presenting as "Signed" to Windows even though its own leaf certificate has expired.
#code-signingabuse#adwarebundler#sandboxevasion#APT28#APT15#crypto-faucetscam#Servers.comhosting#threatintelattributionActorsAPT28 · StrontiumIOCf12 · i3 · d4 · u2MITRE10IndustriesEnergy
APTMembersJul 10, 2026, 19:48 (UTC+9)World Cup Streaming Lures Tie Four Registrars to One Operator
Four landing pages captured in a single infrastructure snapshot all promise the same thing: a live stream of a 2026 FIFA World Cup match. The URLs — watchme.mom/9813/0/fifa/4, sportxlive.sbs/2562/0/soccer%20ss/19, nowstreams.top/player.php/iran-vs-new-zealand-fifa-world-cup-football, and foxtrend.click/event/wc-2026-iran-vs-new-zealand-m — sit on four domains registered through four different registrars, at four different points between February and May 2026.
#LazarusGroup#torpig#WorldCuplure#phishingdomains#Let'sEncryptcertificates#Cloudflarefronting#Namecheapsharedhosting#spearphishinglinkActorsLazarus Group · Hastati GroupIOCf0 · i2 · d5 · u4MITRE4IndustriesEducation & Research · Utilities
APTMembersJul 10, 2026, 19:27 (UTC+9)Expired and Valid Code-Signing Certificates Both Fuel VPN Malware
Three code-signing identities — WEILAI NETWORK TECHNOLOGY CO., LIMITED, Bright Data Ltd, and INNOVATIVE CONNECTING PTE. LIMITED — anchor a cluster of VPN and proxy installers now circulating with a shared defect: the certificates behind them have lapsed, and the binaries keep shipping anyway. The most striking case is a single leaf certificate (serial 03 A9 18 8A A5 10 C0 F8 34 34 26 BF), issued to WEILAI NETWORK TECHNOLOGY under a GlobalSign GCC R45 EV CodeSigning chain, that signs three…
#code-signingabuse#PBotstealer#BrightData#VPNtrojan#expiredcertificate#brandimpersonationdomains#supplychaintrustabuse#commoditymalwareActorsEvilnum · DeathStalkerIOCf21 · i22 · d45 · u3MITRE18
APTMembersJul 10, 2026, 08:36 (UTC+9)Fake UnionPay Certificate Ties Together Eighteen IPs on Nine Chinese Carriers
Fifteen of eighteen catalogued IP addresses, scattered across nine distinct Chinese network operators, present the exact same TLS certificate serial — b16a258a252d804ceb0eb5ba860f3e5 — for a subject that has nothing to do with any of them: *.unionpayintl.com, issued by DigiCert Basic OV G2 TLS CN RSA4096 SHA256 2022 CA1 and valid from September 30, 2025 to October 31, 2026.
#UnionPayimpersonation#code-signingabuse#ChineseCDNinfrastructure#adware/PUA#DigiCertcertificatemill#PubNubRAT#ChinaUnicomAS4837#threatattributionmismatchActorsFIN6 · Skeleton SpiderIOCf84 · i25 · d2 · u1MITRE29
APTMembersJul 10, 2026, 02:42 (UTC+9)Shared Import Table Ties Four AD Attack Tools to One Build Pipeline
A single .NET import-table fingerprint — imphash f34d5f2d4577ed6d9ceec516c1f5a744 — turns up on eight separate files carrying four different public tool identities: SharpHound, Certify, Rubeus, DefenderCheck, and an unlabeled dropper masquerading as RandomName.exe. None of these tools were written by the same author, and none share a codebase.
#SharpHound#Mimikatz#Rubeus#Certify#SafetyKatz#ActiveDirectory#credentialtheft#buildprovenanceActorsSandworm · QuedaghIOCf106 · i0 · d2 · u18MITRE22
APTMembersJul 9, 2026, 18:41 (UTC+9)Packed svchost.exe Dropper Reveals Tor C2 Inside Sparse APT Feed
A single UPX-packed binary sitting inside an otherwise thin indicator set shows a strikingly complete tradecraft arc — from disguised execution through anti-analysis packing to discovery and an anonymized command channel — even though the wider record around it barely holds together. The sample, a 7-megabyte Win32 executable that VirusTotal engines label trojan.dekimine, installs itself as %APPDATA%\pwo6\svchost.exe, borrowing the name of a core Windows process while stashing alternate copies…
#APT-C-35#DonotTeam#trojan.dekimine#UPXpacking#masquerading#TorC2#WMIdiscovery#AkamaicertificatemismatchActorsAPTC35 · Donot TeamIOCf58 · i3 · d0 · u1RegionsPL
APTMembersJul 9, 2026, 10:43 (UTC+9)JScript Downloader Checks Its Own IP Before Calling Home
An unsigned UTF-16 JScript file, submitted four times from three separate sources on the same day, spends its opening moments doing something most invoice-lure malware skips: it pauses, checks whether it is being watched, and looks up its own public IP address before doing anything else. That combination — deliberate sleep cycles tagged internally as "long-sleeps" and "idle," paired with an external-IP self-check against checkip.dyndns.org and reallyfreegeoip.org — is the most concrete and…
#Rockloader#TA505#JScriptdownloader#sandboxevasion#invoicelure#self-signedcertificate#VPSinfrastructure#SSLblocklistActorsTA505 · Hive0065IOCf2 · i1 · d0 · u2RegionsBD · DE · ES · FRIndustriesCommercial Services · Construction · Containers & Packaging
APTMembersJul 8, 2026, 11:18 (UTC+9)Fake Filmora Crack Installer Uses PPI-Style Builder Backend, Tied to APT28
A file calling itself "Wondershare Filmora.exe" — bundled inside a folder path reading "Wondershare Filmora v15.2.5.17803 (x64) Crack 2026 New" — is not a video editor. It is a Nullsoft Installer self-extracting archive that 37 of 75 antivirus engines flag as a trojan downloader, distributed through three Cloudflare-fronted .info domains that carry matching wildcard-SAN TLS certificates and, in one case, an on-demand builder endpoint that mints a fresh installer binary for every click.
#APT28#FancyBear#NSISinstaller#pay-per-install#crackedsoftwarelure#healthcaresector#Cloudflareinfrastructure#wildcardTLScertificateActorsAPT28 · StrontiumIOCf3 · i0 · d3 · u12MITRE23RegionsFR · GR · IT · LKIndustriesHealthcare
APTMembersJul 7, 2026, 10:44 (UTC+9)Sality-Linked Miner Cluster Shares Temp Staging, Not Build Code
Two XMRig-derived cryptomining binaries flagged in the same indicator set carry the identical classification tokens "malxmr" and "smcgr26" — yet their import-table hashes and vhash fingerprints have nothing in common, meaning they were never compiled from the same source tree. What does tie the cluster together is a staging habit: a config file, a miner executable, and an unidentified data blob all drop into randomized six-character hex subfolders inside %TEMP%, a loader convention that…
#SaltySpider#Sality#XMRig#cryptojacking#Romania#Akamaiimpersonation#processmasquerading#commoditymalwareActorsSalty Spider · KuKuIOCf6 · i2 · d1 · u1MITRE32RegionsUSIndustriesRetail
APTMembersJul 6, 2026, 18:48 (UTC+9)Stealer Hosting Cluster Grows: Two New IPs, Panels Span Two Providers
Two IP addresses — 196.251.107.104 and 196.251.107.130 — have just joined a five-node hosting cluster sitting on AS214351, registered to Femo IT Solutions Limited, a UK-listed shell address at 71-75 Shelton Street in London's Covent Garden. Both are new since CTX Team's earlier coverage of a StealC v2 campaign built around Chrome credential-store bypass tooling.
#StealCv2#RedLineStealer#Amadey#Carberp#clipboardhijacker#bulletproofhosting#APT28attribution#TLScertificateabuseActorsAPT28 · StrontiumIOCf8 · i7 · d0 · u15MITRE28RegionsJO
APTMembersJul 1, 2026, 21:58 (UTC+9)TA505 Deploys Formbook via JS Dropper and Wildcard C2 in 35-Country Sweep
A seven-kilobyte RAR archive carrying a single JavaScript file — named to impersonate a routine trade document — is the opening move in an active credential-harvesting campaign that CTX Team has been tracking since early June 2026. The JavaScript dropper, weighing in at 71 KB and bearing the filename Swift_advise_40k$.js, invokes Windows Management Instrumentation for execution, deliberately stalls to outlast automated sandbox analysis, and then beacons over HTTPS to a disposable C2 domain…
#TA505#Formbook#JavaScriptdropper#WMIexecution#businessemailcompromise#wholesaleandmanufacturing#credentialharvesting#disposableC2infrastructureActorsTA505 · Hive0065IOCf3 · i0 · d1 · u2RegionsAE · AU · BG · CAIndustriesAgriculture · Government · Hospitality & Leisure
APTMembersJun 30, 2026, 19:33 (UTC+9)Kimsuky's Zero-Import 'svchow.dll' Evades Sandboxes in Espionage Campaign
A 112 KB Windows DLL carrying zero static imports — not a single function name visible in its import table — is circulating as "svchow.dll," a one-character typosquat of the legitimate svchost.dll, planted in the user-writable AppData\Local directory of compromised machines. The payload's combination of dynamic API resolution, debug-environment detection, and long-sleep delays split automated sandbox verdicts cleanly: one engine flagged it as malware, the other returned CLEAN.
#Kimsuky#DPRK#zero-importDLL#typosquatting#sandboxevasion#foodandbeverage#Jordan#espionageActorsKimsuky · Velvet ChollimaIOCf15 · i0 · d1 · u2MITRE26RegionsJOIndustriesFood & Beverages
APTMembersJun 30, 2026, 18:56 (UTC+9)StrongPity Cycles 44 New Files, Keeps Same C2 Domain
Forty-four new file hashes have joined the StrongPity/Patcher toolset tracked against Jordan's food and beverage sector since CTX Team's earlier look at this cluster — yet not one new domain, IP address, or URL appeared alongside them. Forty-three previously catalogued hashes dropped out of the same window. That lopsided arithmetic is the story here: a build pipeline generating and discarding binaries at volume while the delivery and tasking channel behind them sits completely still.
#StrongPity#Patchermalware#APT-C-41#Promethium#Jordan#foodandbeveragesector#command-and-controlinfrastructure#trojanizedinstallerActorsPromethium · StrongPityIOCf78 · i0 · d1 · u3MITRE30RegionsJOIndustriesFood & Beverages
APTPublicJun 29, 2026, 17:09 (UTC+9)TigerRAT's Five-Layer Anti-Analysis Stack Splits Sandbox Verdicts
A 304-kilobyte Windows executable carrying a PE compile timestamp of October 24, 1998 — a date that predates the x86-64 processor architecture the binary actually requires to run — encapsulates the operational philosophy behind the latest TigerRAT sample tied to Silent Chollima (Andariel). The falsified timestamp is not the most sophisticated trick in the sample's arsenal, but it is the most emblematic: every layer of this implant has been deliberately engineered to mislead, delay, or defeat…
#SilentChollima#Andariel#TigerRAT#custompacker#sandboxevasion#C2infrastructure#DPRKthreatactors#defenseandgovernmenttargetingActorsSilent Chollima · AndarielIOCf1 · i1 · d0 · u1MITRE7
APTMembersJun 28, 2026, 17:04 (UTC+9)Emotet's Canadian Campaign Hides Behind Three-Layer Evasion Stack
A 141-kilobyte Word document circulating in phishing email against Canadian targets carries more infrastructure engineering behind it than its modest file size suggests. The malicious document — an Emotet e2 epoch loader first submitted to VirusTotal on 15 October 2020 and still active in this campaign — sits at the front end of a three-layer hosting architecture that combines Cloudflare origin-masking, automated 89-day TLS certificate rotation, and a dedicated command-and-control node…
#Emotet#TA542#MummySpider#Wordmacrodropper#PowerShelldownloader#compromisedWordPressinfrastructure#Canada#CloudflareevasionActorsEmotet Group · TA542IOCf3 · i1 · d3 · u5RegionsCA
APTMembersJun 28, 2026, 16:53 (UTC+9)Decade-Old German Domains Reactivated as Emotet C2 Backbone Targeting Philippines
Six command-and-control domains now active in an Emotet campaign targeting the Philippines share a striking infrastructure characteristic: four of them were registered between 2005 and 2012 through a single German registrar, Cronon GmbH, and have been sitting dormant — or at least benign-facing — for years, accumulating the kind of domain-age legitimacy that reputation-based defences routinely reward with a pass.
#Emotet#TA542#Philippines#CrononGmbH#domainaging#C2infrastructure#macromalware#credentialharvestingActorsEmotet Group · TA542IOCf4 · i0 · d6 · u11RegionsPH
APTMembersJun 28, 2026, 01:25 (UTC+9)Shared Imphash Ties Four 'Different' Stealers to One Builder Stub
Four Windows executables carrying four unrelated antivirus labels — AgentTesla, Bobik, "Reline," and an unnamed loader named pctool.exe — turn out to share the same import-table fingerprint, imphash f34d5f2d4577ed6d9ceec516c1f5a744, and the same PEiD packer signature. That single build lineage is the most durable and reproducible signal in an 18-file, 6-domain cluster CTX Team has been tracking: a commodity builder-and-stub layer that antivirus vendors are classifying as though it produced four…
#RedlineStealer#AgentTesla#Bobik#Socelars#Fabookie#LazarusGroup#pay-per-installdistribution#imphashclusteringActorsLazarus Group · Hastati GroupIOCf18 · i3 · d6 · u17RegionsFR
APTPublicJun 27, 2026, 21:07 (UTC+9)Donot Team Hides Cryptominer Behind Tor C2 and Anti-VM Evasion
A single 7,149-kilobyte Windows executable — packed, obfuscated, and deliberately named to impersonate a core Windows process — encapsulates one of the more analytically provocative payload configurations CTX Team has observed in a recent APTC-35 dataset. The binary, classified as trojan.dekimine and bearing the meaningful installation path %APPDATA%\pwo6\svchost.exe, does not merely steal data or open a remote shell.
#APTC-35#DonotTeam#dekimine#cryptomining#TorC2#sandboxevasion#Poland#UPXpackingActorsAPTC35 · Donot TeamIOCf58 · i1 · d0 · u0MITRE29RegionsPL
APTMembersJun 27, 2026, 16:55 (UTC+9)Seven Hostnames, One Timestamp: Mapping the yazanboss Dynamic-DNS Block
Seven near-identical hostnames — 1yazanboss.no-ip.biz through 6yazanboss.no-ip.biz, plus a bare yazanboss.no-ip.biz — were all created at the exact same second, 2001-11-22T23:09:02Z, under a single Vitalwerks Internet Solutions, LLC / No-IP.com account, with matching admin and billing contacts listed out of Reno, Nevada on every WHOIS record.
#yazanboss#DynamicDNS#No-IP.com#Sality#SaltySpider#USB-autorun#polymorphicpacker#retailsectorActorsSalty Spider · KuKuIOCf6 · i0 · d7 · u0MITRE49RegionsUSIndustriesRetail
APTMembersJun 26, 2026, 20:56 (UTC+9)APT29's 2013 MiniDuke Implant Still Beaconing via Aftermarket Domain in 2026
Sixty-three of 76 antivirus engines correctly identify the 326-kilobyte Windows executable bearing SHA-256 05e4224d4dd4e5fbd381ed33edb5bf847fbc138fbe9f57cb7d1f8fc9fa9a382d as a MiniDuke Stage 3 trojan — yet one of only two sandboxes that processed it returned a 97-percent-confidence verdict of harmless. That split is not a data anomaly. It is the point.
#APT29#MiniDuke#HongKong#sandboxevasion#C2infrastructure#espionage#aftermarketdomain#dynamicanalysisevasionActorsAPT29 · MinidionisIOCf1 · i0 · d1 · u34MITRE12RegionsHK
APTMembersJun 26, 2026, 17:09 (UTC+9)Sims 4 Crack Installer Still Feeds Same CyberGate RAT
Two unsigned Windows executables masquerading as pirated copies of "The Sims 4" — both stamped with the identical PE build timestamp of 2025-03-13, both traced through directory paths reading `setup_TS4.exe and setup_TS4.tmp — sit at the center of a small but instructive campaign that pairs a piracy lure with a fully evasion-aware RAT/keylogger payload. What makes this cluster notable isn't its scale; it's the discipline.
#DustSquad#CyberGate#KeyloggerGeneric#Sims4crackinstaller#dynamicDNSC2#sandboxevasion#telecomsectortargeting#NSISdropperActorsDustSquad · APTC34IOCf10 · i0 · d1 · u1MITRE35RegionsCH · ES · KR · PLIndustriesTelecommunications
APTMembersJun 26, 2026, 09:21 (UTC+9)Cobalt Strike Loader Masks as Crash-Reporter, Hides Behind Default TLS Cert
A loader package built inside a single four-minute window in December 2024 bundles a Windows executable and two DLLs designed to look like ordinary Windows utility software — one impersonating a game-crash reporting library, the other borrowing the name of a print-spooler helper. Once unpacked, the components stall, check for a debugger, and wait for a human to interact with the machine before doing anything else, a staging sequence built specifically to survive automated malware sandboxes.
#CobaltStrike#Barium#Blackfly#PassCV#loadermalware#sandboxevasion#C2infrastructure#espionageActorsBarium · Wicked SpiderIOCf5 · i1 · d0 · u1MITRE32RegionsCHIndustriesSupport Services
APTMembersJun 26, 2026, 01:23 (UTC+9)Decade-Old Keygen Trojan Anchors Multi-Stage Pakistan Espionage Chain
Since CTX Team's earlier coverage of this operation, six new files have surfaced that materially deepen the picture of how the Godzilla Loader and PonyStealer campaign targeting Pakistan actually functions — not just what it delivers, but how it gets there. The new components introduce a second build cluster absent from prior analysis: a batch-script orchestrator, an invalid-signed SOCKS5 proxy tool, a PEiD-packed .NET spreader, and a delivery archive built around a keygen lure that has been…
#GodzillaLoader#PonyStealer#Pakistanespionage#keygentrojan#SOCKS5proxy#credentialtheft#C2infrastructure#spreadermalwareIOCf17 · i0 · d5 · u9MITRE34RegionsPK
APTMembersJun 25, 2026, 20:56 (UTC+9)EV Certificate Minted for One Campaign Powers Three-Layer Evasion Chain
Thirty-nine days. That is the total operational window separating the moment a Sectigo Extended Validation certificate was issued to an entity called QUANTIS LOGIK LTD and the moment the two PE32 installers it signed first appeared on VirusTotal. The certificate — serial number 00 86 51 B4 B7 A5 AF 08 DF 82 E5 FE 4E 5B 99 A8 18, thumbprint 1080D4CCFE6E5EE372CB3DB8686C37923A932AF5, issued 2026-04-22, used to sign both payloads on 2026-05-19, with the files submitted on 2026-06-01 — was not a…
#LummaStealer#OfferCore#EVcertificateabuse#CloudFrontdomain-fronting#sandboxevasion#LazarusGroup#telecomsector#code-signingabuseActorsLazarus Group · Hastati GroupIOCf2 · i0 · d1 · u0MITRE21RegionsCO · DE · EG · FRIndustriesAgriculture · Support Services · Telecommunications
APTPublicJun 24, 2026, 21:30 (UTC+9)TA505 Rockloader C2 Hits SE Asia Finance With Zero Detections
Three command-and-control domains registered within five weeks of each other, scoring zero detections across 91 antivirus engines, with WHOIS identity fields uniformly padded with the same 16-character hex string — this is the operational signature CTX Team has mapped to a TA505-attributed rockloader campaign currently targeting financial-services organisations in Cambodia and Singapore.
#TA505#rockloader#command-and-controlinfrastructure#financialservices#Cambodia#Singapore#DGA#WHOISobfuscationActorsTA505 · Hive0065IOCf9 · i0 · d3 · u0MITRE32RegionsKH · SGIndustriesFinancial Services
APTMembersJun 24, 2026, 01:23 (UTC+9)Fake YCleanner App Delivers LummaStealer After Four-Month Build Campaign
A Windows executable branded as a system-cleaning utility — product name "YCleanner," internal name YC.exe, version 1.3.2.5 — has been circulating as the delivery vehicle for a dual-purpose attack chain combining LummaStealer credential theft with XMRig cryptomining, targeting Romania. The campaign's most operationally distinctive feature is not the payload itself but the architecture surrounding it: an encrypted outer container that achieves a clean sweep of 0/77 antivirus detections at the…
#BlueBottle#LummaStealer#XMRig#Romania#credentialtheft#cryptomining#fakesoftwarelure#Opera1erActorsBlueBottle · Opera1erIOCf16 · i0 · d1 · u1RegionsRO
APTMembersJun 23, 2026, 00:58 (UTC+9)Trojanised Adobe Firefly Installer Runs Triple-Monetisation Kill Chain on Construction Firms
Pirated creative software has long been a reliable vector for commodity malware, but a campaign CTX Team has been tracking shows how far that distribution model has matured. Two oversized Windows executables — both named FireflyAI.exe, one weighing 45 MB and the other 53 MB — are circulating as trojanised installers for Adobe's Firefly AI tool, with one sample's embedded path string explicitly referencing "Firefly AI 25.0.0.2265 beta for Adobe Photoshop 24.7 (x64)." The lure has been active…
#PureLogs#WinRing0BYOVD#Nanopool#trojanisedinstaller#constructionsector#credentialtheft#crypto-mining#C2infrastructureActorsAPT28 · StrontiumIOCf21 · i4 · d5 · u4RegionsBR · DE · LUIndustriesConstruction
APTMembersJun 21, 2026, 16:13 (UTC+9)Emotet Hijacks Aged German Sites to Evade Detection in PNG Campaign
Four German-hosted websites — three of them registered between 2000 and 2009, all of them delegating DNS through the same Cronon/Strato nameserver infrastructure — are serving as the distribution backbone for an active Emotet campaign targeting the hospitality sector in Papua New Guinea. The cluster, observed by CTX Team between 14 and 21 June 2026, is analytically notable not for the malware it delivers but for the hosting architecture it exploits: rather than spinning up fresh…
#Emotet#TA542#CrononGmbH#rzone.de#hospitalitysector#PapuaNewGuinea#compromisedlegitimatedomains#PowerShelldownloaderActorsEmotet Group · TA542IOCf4 · i1 · d4 · u8RegionsPGIndustriesHospitality & Leisure
APTMembersJun 21, 2026, 04:00 (UTC+9)Kimsuky Hides Trojan in Npcap Installer With Valid Nmap Certificate
A Nullsoft NSIS self-extracting installer bearing the filename npcap-1.88-oem-usnavy-testcopy-poexcu.exe — signed with a fully valid Nmap Software LLC code-signing certificate and scoring zero detections across 76 antivirus engines — represents one of the more deliberate evasion constructions CTX Team has documented in recent months.
#Kimsuky#GuLoader#Npcap#code-signingabuse#driver-storemasquerading#defencesector#sandboxevasion#AuthenticodeoverlayActorsKimsuky · Velvet ChollimaIOCf33 · i0 · d0 · u0MITRE44
APTMembersJun 20, 2026, 16:10 (UTC+9)APT28 Hides Trojan in Pirated Software, Spreads via USB Across 22 Countries
A 2,967-kilobyte Windows executable dressed up as "FL Studio 2025 Full Version.exe" is circulating across manufacturing and telecom networks in 22 countries, carrying a layered evasion stack that defeated one of three automated sandboxes outright — and the certificate stapled to it was issued the same day the file first appeared on VirusTotal, minted by a service that signs anything you give it.
#APT28#trojan#USBspreader#piratedsoftwarelure#manufacturing#telecommunications#sandboxevasion#WMIexecutionActorsAPT28 · StrontiumIOCf1 · i1 · d3 · u3MITRE11RegionsAO · AR · AU · BOIndustriesManufacturing · Telecommunications
APTMembersJun 20, 2026, 15:58 (UTC+9)Snowglobe Adds Chrome-Extension Droppers, Leaves cheater.to Untouched
Six new file indicators have joined the record CTX Team has been building around a Cloudflare-fronted domain called cheater.to — and none of them are new domains or IPs. That distribution alone is the story. The most consequential pair in the batch are two files that VirusTotal types as "Google Chrome Extension" containers, complete with the magic string "Google Chrome extension, version 3, XZ compressed, CRC64" — yet whose internal file paths resolve to ordinary Windows executables:…
#Snowglobe#Babar#Vidarstealer#Salatstealer#masqueradingT1036#telecomespionage#cheater.to#CloudflareinfrastructureActorsSnowglobe · Animal FarmIOCf9 · i0 · d1 · u0MITRE43RegionsCZ · LT · SA · TRIndustriesTelecommunications
APTMembersJun 19, 2026, 03:56 (UTC+9)Spring Dragon Hides GCleaner in VR Installer With 4-Year-Old Certificate
A Windows executable posing as an HTC VIVE Software installer has surfaced carrying a DigiCert code-signing certificate that expired in April 2021 — more than four years before the file appeared on any scanner — while beaconing to a trio of command-and-control domains registered, TLS-provisioned, and Cloudflare-proxied within a single 72-hour window.
#SpringDragon#GCleaner#wmi_ghost#code-signingcertificateabuse#sandboxevasion#CloudflareC2proxying#HTCVIVElure#pay-per-installloaderActorsSpring Dragon · Lotus BlossomIOCf1 · i0 · d3 · u6MITRE12
APTPublicJun 18, 2026, 23:57 (UTC+9)Upatre Dropper Fires CryptoLocker Rules as Decade-Dormant Domain Wakes
A 27-kilobyte Windows executable named case_10022013.exe sits at the centre of a delivery chain that has been quietly circulating since at least October 2013 — and the most analytically striking detail is not its age but its identity crisis. The binary is classified by 66 of 77 antivirus engines as Upatre, the compact downloader long associated with the Gold Evergreen / Business Club criminal ecosystem.
#GoldEvergreen#BusinessClub#Upatre#CryptoLocker#ZBot#legal-lurephishing#long-dormantC2infrastructure#dual-familymalwareActorsGold Evergreen · Business ClubIOCf3 · i0 · d1 · u1MITRE9
APTMembersJun 18, 2026, 15:58 (UTC+9)Forged 72-Hour Certificates Hid WarzoneRAT From All 76 AV Engines
Seven Windows executables and DLLs, all signed under the name of a legitimate German digital-publishing company, arrived on VirusTotal on 23 May 2026 with a combined static detection score of zero across 76 engines. The files presented themselves as components of "t-online Browser 7," a real product distributed by Ströer Digital Publishing GmbH — complete with version strings, Mozilla Public License 2.0 copyright notices, and Authenticode signatures rooted in Microsoft's own…
#APT28#WarzoneRAT#Winos4.0#Skip-2.0#code-signingabuse#energysector#GermanyFranceLuxembourg#AuthenticodeActorsAPT28 · StrontiumIOCf55 · i0 · d0 · u0MITRE55RegionsDE · FR · LUIndustriesEnergy · Technology · Telecommunications
APTMembersJun 18, 2026, 04:04 (UTC+9)NullMixer Bundle Drops Five Malware Families via Discord Fake Installer
A single Windows executable masquerading as a software setup wizard unpacks at least five distinct malware families the moment a user double-clicks it — RedlineStealer, ClipBanker, SmokeLoader, StealBit, and Upatre arriving as a coordinated bundle rather than a sequential chain. That delivery model, confirmed by the Malpedia YARA rule win_nullmixer_auto firing on two large installer files and by unanimous sandbox verdicts naming four families simultaneously, is the operationally distinctive…
#APT28#NullMixer#RedlineStealer#SmokeLoader#ClipBanker#DiscordCDNabuse#Bolivia#fakeinstallerActorsAPT28 · StrontiumIOCf18 · i3 · d4 · u10RegionsBO
APTMembersJun 17, 2026, 23:57 (UTC+9)DHL-Lure RAR Delivers MassLogger to Construction Firms Across Four Countries
A 946-kilobyte RAR archive named DHL_AWB#6078538091.rar has been circulating since mid-May 2026 as the opening move in a credential-harvesting campaign targeting construction-sector organisations across Germany, India, Malaysia, and Turkey. The archive is not simply a container — it is itself the first evasion layer, carrying explicit debugger-detection and long-sleep logic that caused one major automated analysis platform to return a clean verdict at 96% confidence while a second correctly…
#APT29#MassLogger#Formbook#credentialharvesting#constructionsector#sandboxevasion#spear-phishing#processinjectionActorsAPT29 · MinidionisIOCf3 · i0 · d0 · u0MITRE23RegionsDE · IN · MY · TRIndustriesConstruction
APTMembersJun 17, 2026, 20:00 (UTC+9)Salat Stealer Bypasses Chrome v127 Encryption in Capability Leap
A 12-megabyte unsigned Windows executable first observed on 2 May 2026 carries a capability set that goes well beyond what commodity stealers typically offer: a working Chromium app-bound encryption decrypter, a large embedded catalogue of cryptocurrency wallet browser-extension identifiers, and a command-and-control resolution path routed through Cloudflare's DNS-over-HTTPS service to defeat the DNS-layer monitoring that would otherwise expose its infrastructure.
#SalatStealer#Chromiumapp-boundencryptionbypass#DNS-over-HTTPSevasion#credentialtheft#cryptocurrencywalletharvesting#APT28#CloudflareCDNabuse#browsercredentialstoresActorsAPT28 · StrontiumIOCf1 · i2 · d3 · u2MITRE11
APTMembersJun 17, 2026, 13:49 (UTC+9)APT10's 2016 ChChes Implant Runs on C2 Renewed in 2025
A 283-kilobyte Windows executable compiled in November 2016 carries a code-signing certificate that expired more than a decade ago — yet the command-and-control domain it phones home to received a fresh TLS certificate as recently as September 2025. That tension between aged tooling and actively maintained infrastructure is the defining characteristic of a ChChes implant attributed to Red Apollo (APT10) that CTX Team has been tracking since December 2024.
#RedApollo#APT10#ChChes#OperationCloudHopper#code-signingabuse#C2infrastructure#sandboxevasion#espionageActorsRed Apollo · PotassiumIOCf1 · i0 · d1 · u5MITRE13
APTMembersJun 17, 2026, 13:31 (UTC+9)Scripted CKEditor Exploitation Endpoints Surface Across Two Campaign Domains
Four newly documented URLs targeting the CKEditor-for-WordPress plugin across two domains — kartacnictvi.cz and mokawafm.com — now explicitly expose the scripted initial-access mechanism behind a campaign CTX Team has been tracking in connection with a Lazarus Group CRAT implant. Each URL follows the same path structure — wp-content/plugins/ckeditor-for-wordpress/ckeditor/plugins/image/ — and carries a hex-timestamp query parameter: ts=6A4310F7_1897026C, ts=6A431118_12AB12AC,…
#LazarusGroup#CRAT#Nukesped#Zusy#WordPressCKEditor#Jordan#foodandbeverages#initialaccessActorsLazarus Group · Hastati GroupIOCf2 · i2 · d2 · u6MITRE19RegionsJOIndustriesFood & Beverages
APTMembersJun 17, 2026, 10:08 (UTC+9)TA505 Fake Purchase Order Hides JS Payload 70 Engines Cannot See
A spear-phishing campaign attributed to TA505 is circulating a Varist-packed RAR archive named after a fake purchase order — but the real detection problem sits one extraction step deeper: the JavaScript payload inside evades 70 of 76 antivirus engines despite both sandboxes that processed it returning unambiguous malicious verdicts, and despite an Abuse.ch IDS rule already flagging its PureHVNC command-and-control certificate.
#TA505#PureHVNC#JavaScriptdropper#spear-phishing#procurementsector#sandboxevasion#Unicodeobfuscation#dormantdomainreactivationActorsTA505 · Hive0065IOCf2 · i0 · d1 · u2RegionsCY · DE · DK · FRIndustriesRetail · Support Services · Technology