APT
164 stories
APTMembersMay 28, 2026, 01:59 (UTC+9)Ludashi Campaign Adds 13 Payloads, Tencent CDN Relay to Evasion Stack
Thirteen new Windows PE32 binaries signed under a single DigiCert code-signing certificate have entered the Ludashi-ecosystem campaign since CTX Team's prior coverage, while a freshly provisioned four-subdomain C2 cluster under tjbxldkj.cn and a Tencent Cloud API Gateway domain-fronting relay on ss.dllfix.cn represent infrastructure capabilities that were absent from the earlier operation.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf32 · i23 · d6 · u8MITRE12
APTMembersMay 27, 2026, 06:02 (UTC+9)Trojanised Office Tool Hides Multi-Stage Intrusion Behind Streaming C2
A trojanised version of OfficeRTool — a popular Microsoft Office removal and activation utility distributed through piracy channels — is serving as the entry point for a disciplined, multi-phase intrusion operation that layers sandbox-evading VBScript components, a vhash-identical PowerShell downloader maintained across at least six major tool versions, expired-certificate network reconnaissance, and a command-and-control channel engineered to look indistinguishable from HLS media streaming…
#LockbitGang#expiro#GovernmentActorsLockbit GangIOCf7 · i3 · d2 · u8MITRE11IndustriesGovernment
APTMembersMay 27, 2026, 05:51 (UTC+9)Expired-Cert Installer Evades Sandboxes, Feeds 15-Domain Crypto Fraud Net
A 4.3-megabyte Windows installer, dressed in the branding of legitimate freeware and carrying a Sectigo-issued code-signing certificate that had already expired, is the entry point for a financially motivated campaign that routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains.
#APT28#APT15#bumblebee#EnergyActorsAPT28 · StrontiumIOCf62 · i6 · d15 · u11MITRE12IndustriesEnergy
APTMembersMay 27, 2026, 00:03 (UTC+9)APT28 Splits EV Certificate and LummaC2 Stealer Across Two-Tier Chain
Four Windows executables carrying a valid Extended Validation code-signing certificate issued to an entity called ORYON TECH LIMITED are circulating as a disguised system-utility package — while a pair of freshly compiled LummaC2 stealers, deliberately stripped of any trusted certificate chain, rides the same delivery infrastructure toward the same targets. The deliberate split is not an oversight.
#APT28#gcleaner#TechnologyActorsAPT28 · StrontiumIOCf21 · i2 · d5 · u8RegionsUSIndustriesTechnology
APTMembersMay 26, 2026, 23:45 (UTC+9)Signed, Sealed, Trojanized: Dual Chengdu Certs Power RAT Campaign
Eighteen Windows PE32 files — executables and DLLs impersonating Ludashi SuperApp system utilities — are circulating with currently-valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, producing uniformly clean sandbox verdicts despite industry detection ratios that reach as high as 34 of 76 engines.
#Turla#FIN6#Group123#lockergoga#ncctrojan#xtreme_ratActorsTurla · Iron HunterIOCf57 · i27 · d7 · u1MITRE16IndustriesTelecommunications
APTMembersMay 26, 2026, 22:24 (UTC+9)FunkSec macOS Implant Evades 76 AV Engines via Fake Chrome Signing
Two Mach-O universal binaries named com.google.Chrome.helper — each 166 kilobytes, each signed with a structurally present but functionally invalid Google LLC code-signing certificate, each returning zero detections across all 76 antivirus engines on VirusTotal — are circulating as part of a campaign CTX Team has attributed to FunkSec, targeting engineering and government sector organisations operating macOS endpoints.
#FunkSec#Engineering#GovernmentActorsFunkSecIOCf2 · i12 · d47 · u31MITRE8IndustriesEngineering · Government
APTMembersMay 26, 2026, 22:03 (UTC+9)Salty Spider Turns Revoked Certificates Into a 71/76 Evasion Tool
Two Windows executables submitted to public malware repositories on 23 May 2026 — both signed with a code-signing certificate that had already been revoked by its issuing CA — cleared 71 of 76 scanning engines without triggering a single alert. The files, bearing the product description "Pro解压缩" (Pro Decompression) and the internal name uninst.exe, were the freshest output of a campaign that CTX Team has been tracking across a ten-month arc stretching from July 2025 to the present.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf15 · i1 · d8 · u3MITRE42
APTMembersMay 26, 2026, 16:35 (UTC+9)Two DigiCert Certs, 18 Signed Payloads, 14 Months Unrevoked
Eighteen Windows executables and DLLs have been circulating under the cover of two valid DigiCert Trusted G4 code-signing certificates, each issued to a distinct Chinese legal entity, across a campaign that CTX Team has tracked from November 2024 through at least January 2026. Both certificates remain unrevoked. Every file in the cohort passes Windows Authenticode validation without a SmartScreen warning.
#FIN6#SaltySpider#lockergoga#lummastealer#salityActorsFIN6 · Skeleton SpiderIOCf32 · i8 · d10 · u12MITRE19
APTMembersMay 26, 2026, 10:12 (UTC+9)Trojanized Adware Chain Hides Behind Bank's TLS Identity for 12 Months
Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 have been circulating as trojanized PC-utility components since at least May 2025 — all signed under a single certificate serial (0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0) that remains unrevoked and valid through May 2027.
#FIN6#lockergoga#lummastealer#expiro#TelecommunicationsActorsFIN6 · Skeleton SpiderIOCf20 · i18 · d0 · u1MITRE8IndustriesTelecommunications
APTMembersMay 26, 2026, 09:59 (UTC+9)Single EV Certificate Signed Trojan.Jumper Trio Across Nine Sectors
A trojanised VPN installer toolchain — three PE32 binaries all bearing a single GlobalSign Extended Validation certificate issued to "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — has been circulating across nine industry verticals since at least September 2025, using a curated software-recommendation channel as its entry point and a three-tier command-and-control architecture to evade both sandbox analysis and network-level detection.
#TA551#EducationResearch#Engineering#Financial#FoodBeverages#GovernmentActorsTA551 · ShathakIOCf3 · i4 · d2 · u1MITRE29IndustriesEducation & Research · Engineering · Financial Services
APTMembersMay 26, 2026, 09:41 (UTC+9)APT23 Runs 18-Month Signed-Binary Campaign Behind Chinese Corporate Certs
Eight Windows executables have been circulating across Chinese-language computing environments since at least November 2024, each carrying a valid, unexpired DigiCert G4 code-signing certificate issued to one of three distinct Chinese corporate entities — and each producing uniformly clean verdicts in automated sandbox environments despite antivirus detection ratios that range as high as 34 out of 76 engines.
#APT23#lummastealer#icedid#neshtaActorsAPT23 · KeyBoyIOCf12 · i2 · d9 · u11MITRE13
APTMembersMay 24, 2026, 17:57 (UTC+9)One Unrevoked Certificate, 17 Payloads, Eleven Months of Signed Adware
Seventeen distinct Windows executables. Six product identities. Eleven months of continuous distribution. All of it bound together by a single DigiCert G4 code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co., Ltd.) — a certificate that, as of this writing, remains valid, unrevoked, and good until May 2027.
#FIN6#Group123#SaltySpider#lockergoga#lummastealer#salityActorsFIN6 · Skeleton SpiderIOCf34 · i3 · d6 · u6MITRE11
APTMembersMay 24, 2026, 14:01 (UTC+9)Salty Spider Hides RAT in Signed Bundles via Two DigiCert Certs
Twenty malicious Windows executables and DLLs have been circulating under valid DigiCert G4 code-signing certificates issued to two Chinese-registered front entities — a dual-certificate architecture that has remained unrotated across a fifteen-month active build window while the operator quietly embedded a PubNubRAT remote-access capability inside what presents to users as a routine system-utility bundle.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf33 · i7 · d6 · u5MITRE14
APTMembersMay 24, 2026, 13:30 (UTC+9)Cactus Group Abuses Three Signing Identities to Hide PBot Stealer in VPN Lures
Nine Windows executables circulating across software-distribution channels share a single operational logic: every one of them carries a legitimate code-signing certificate — or a certificate that was legitimate until recently — and every one of them is doing something the signer never intended. Six files exploit expired-but-chain-valid EV and OV certificates from two distinct corporate identities to suppress antivirus detection on trojanized VPN installers.
#Cactus#ramnitActorsCactus · Cactus Ransomware GroupIOCf16 · i46 · d118 · u16MITRE16