C&C
176 stories
C&CMembersMay 30, 2026, 23:28 (UTC+9)Phorpiex Botnet Splits C2 Across Russian and AFRINIC Hosts to Resist Takedown
A single 14-kilobyte Windows executable — compact enough to fit in a single memory page — is beaconing outward to two command-and-control servers that have been deliberately placed in different corners of the internet's address space. One sits inside a subnet allocated to Prospero OOO, a St. Petersburg-registered provider operating under AS200593 through RIPE NCC, and carries a short-lived Let's Encrypt certificate for the domain "ledgersinsured.com" as its TLS cover.
#Phorpiex#botnetC2infrastructure#ProsperoOOO#AFRINIC#ransomware#Uzbekistan#TLScertificateabuse#wormpropagationIOCf1 · i2 · d0 · u8MITRE47RegionsUZ
C&CMembersMay 30, 2026, 07:04 (UTC+9)Trojanised VPN Installer Weaponises Two Legitimate Code-Signing Chains
A 14.5-megabyte NSIS self-extracting archive named WireVpn_v3.6.0.3-6872e76.exe has been circulating through a curated software-distribution channel labelled "TS Recommended Apps" — bearing a valid Extended Validation code-signing certificate from GlobalSign, issued to a Chinese-registered entity called WEILAI NETWORK TECHNOLOGY CO., LIMITED, and dropping kernel-level netfilter drivers alongside proxy and jumper binaries that collectively form an espionage-oriented command-and-control platform.
#WireVPN#PBot#WEILAINETWORKTECHNOLOGY#BrightDataSDK#code-signingabuse#netfilterkerneldriver#signedbinaryproxyexecution#credentialstealerActorsSprite Spider · Gold DupontIOCf27 · i27 · d94 · u12MITRE24
C&CMembersMay 30, 2026, 00:50 (UTC+9)Sequential C2 Panel Paths Expose Seychelles-Registered Bulletproof Hosting Behind Spain Infostealer Campaign
Three new command-and-control IP addresses have surfaced in the latest observation window of a SmokeLoader and Rhadamanthys infostealer campaign targeting victims in Spain — and the way those addresses were provisioned tells a more precise story than the malware families themselves. Two of the IPs share a single autonomous system number, AS202412, registered to Omegatech LTD, a Seychelles-incorporated entity whose RIPE NCC address block allocations were created within a single month of each…
#SmokeLoader#Rhadamanthys#bulletproofhosting#credentialtheft#Spain#cryptocurrencywallettheft#C2infrastructure#infostealerActorsAPT28 · StrontiumIOCf34 · i3 · d0 · u4MITRE49RegionsES
C&CMembersMay 29, 2026, 20:56 (UTC+9)Six-Year-Old Phorpiex Dropper Hits Kazakhstan on Fresh Romanian VPS
A 412-kilobyte Windows executable — unsigned, packed, and masquerading as a tape-toolbar utility from the year 2000 — has been actively beaconing to a freshly provisioned Romanian virtual private server since at least March 2026, deploying a three-capability payload stack against education and government targets in Kazakhstan.
#Phorpiex#ClipBanker#USBworm#Kazakhstan#educationsector#governmentsector#clipboardhijacking#commoditybotnetIOCf8 · i1 · d0 · u10MITRE36RegionsKZIndustriesEducation & Research · Government
C&CMembersMay 29, 2026, 14:28 (UTC+9)PBot Stealer Gets 64-Bit Rebuild, Drops to 9/76 Detections
Since CTX Team's earlier coverage of this VPN-lure PBot stealer campaign, the most operationally significant development is not the expansion of the domain or IP set — though both have grown substantially — but a single freshly compiled binary that signals the operator is actively retooling the payload build pipeline rather than coasting on existing artifacts.
#ramnit#beaconIOCf9 · i28 · d51 · u6MITRE23
C&CMembersMay 28, 2026, 22:40 (UTC+9)Trojanized Security Suite Uses Valid DigiCert Cert to Blind Sandboxes
Nine PE32 components masquerading as a legitimate Chinese consumer security product are circulating with a currently-valid DigiCert code-signing certificate, a direct-syscall evasion technique confirmed by YARA, and payload delivery routed through Alibaba's KunlunCan CDN — a combination that collapses sandbox verdicts to zero while roughly half of antivirus engines still flag the files on static analysis alone. The gap between those two numbers is the operational story of this campaign.
#SaltySpider#salityActorsSalty Spider · KuKuIOCf9 · i21 · d2 · u5MITRE22
C&CMembersMay 28, 2026, 22:28 (UTC+9)One DigiCert Cert, 14 Executables, Nine Months Undetected
Fourteen distinct Windows executables. Six different product personas. One code-signing certificate — and nine months of continuous, largely undetected operation. That is the operational picture CTX Team has assembled from a cluster of signed PE32 binaries circulating through the Ludashi PUA distribution ecosystem, all stamped with a single DigiCert certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid through 2027-05-20).
#FIN6#Group123#SaltySpider#lockergoga#salityActorsFIN6 · Skeleton SpiderIOCf23 · i25 · d4 · u1MITRE11
C&CMembersMay 28, 2026, 18:31 (UTC+9)One EV Certificate, Two Trojans, Three Fake Windows Binaries
Two trojan.jumper payloads circulating under the guise of a WireVPN client share an identical GlobalSign Extended Validation code-signing certificate — serial 03 A9 18 8A A5 10 C0 F8 34 34 26 BF, issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED — while three companion files masquerade as canonical Windows system executables, carrying valid Microsoft signatures and zero detections across 76 scanning engines.
#beacon#AutomotiveIOCf6 · i6 · d6 · u0MITRE12IndustriesAutomotive
C&CMembersMay 28, 2026, 18:11 (UTC+9)Space Pirates Add Signed .NET Stealer to Trojanized-VPN Arsenal
Since CTX Team's earlier coverage of this campaign, eight new malicious files and a complete refresh of 18 IP addresses and 26 domains have surfaced — but the most operationally significant development is not the scale of the infrastructure turnover. It is the addition of a third signed-binary abuse vector: a Dotfuscator-packed, encrypted .NET stealer classified as PBot, hidden inside a binary carrying a valid Bright Data Ltd code-signing certificate.
#SpacePirates#ramnit#beaconActorsSpace Pirates · WebwormIOCf14 · i18 · d26 · u4MITRE17
C&CMembersMay 28, 2026, 06:11 (UTC+9)Ludashi PUA Pivots to Cloud-Fronted C2 via Tencent API Gateway
Since CTX Team's earlier coverage of the Ludashi PUA campaign, the observable infrastructure has undergone a complete turnover: twelve new IP addresses, six new domains, and seven new URLs have entered the active indicator set, while every previously tracked file has rotated out. The payload layer is quiet — zero new binaries — but the network layer tells a story of deliberate, operationally sophisticated infrastructure replacement.
#TA551#icedidActorsTA551 · ShathakIOCf19 · i12 · d6 · u7MITRE12
C&CMembersMay 28, 2026, 02:13 (UTC+9)Fake Speed-Test Utility Hides Eight-Year C2 Network With *.malware.com Cert
Two subdomains. One IP address. One self-signed TLS certificate whose common name is literally *.malware.com. The infrastructure behind a shlayer-attributed potentially unwanted program (PUP) campaign targeting the energy sector is not subtle — but its longevity is. The parent domain buffernavpose.com was registered on 2018-05-12 via Dynadot Inc, has been actively maintained through at least April 2026, and carries a certificate valid until 2030-05-11.
#shlayer#EnergyIOCf2 · i0 · d2 · u10MITRE15IndustriesEnergy
C&CMembersMay 27, 2026, 21:54 (UTC+9)Six-Year-Old Batch Script Powers 2025 Telecom Espionage Campaign
A trojanised ZIP archive impersonating the legitimate Microsoft Activation Scripts open-source project is circulating across enterprise endpoints, embedding active sandbox-evasion logic inside what victims perceive as a trusted Windows activation utility — and funnelling compromised hosts toward a freshly constructed, deliberately compartmentalised command-and-control infrastructure spanning three distinct autonomous systems with no cross-node certificate or DNS linkage between them.
#TA505#Cactus#goldeneye#TelecommunicationsActorsTA505 · Hive0065IOCf2 · i2 · d1 · u17MITRE4IndustriesTelecommunications
C&CMembersMay 27, 2026, 18:11 (UTC+9)WireVPN Campaign Adds 132 Domains and a PBot Stealer Component
Fifty-five new command-and-control IPs and 132 additional domains have joined the Trojan.Jumper/WireVPN campaign's observable footprint since CTX Team's earlier coverage, transforming what was a 15-domain, 9-ASN operation into a multi-continent hosting fabric organised across five named fingerprint clusters. The expansion is not random: every cluster is bound by a shared certificate issuer, autonomous system, or registrar identity, and the core payload chain — three PE32 executables all signed…
#SpacePirates#CactusActorsSpace Pirates · WebwormIOCf4 · i55 · d132 · u19MITRE14
C&CMembersMay 27, 2026, 17:56 (UTC+9)Salty Spider Expands to Dual-Domain C2 With UnionPay TLS Fingerprint
Nine command-and-control domains, nine documented URL paths, and 31 IP addresses — none present in prior coverage — have surfaced in the latest observed activity tied to the Salty Spider campaign, exposing for the first time the full operational infrastructure behind a signed-binary adware toolkit that CTX Team has been tracking across multiple observation windows.
#SaltySpider#lummastealer#salityActorsSalty Spider · KuKuIOCf51 · i31 · d9 · u9MITRE8
C&CMembersMay 27, 2026, 13:52 (UTC+9)Trojan.Jumper Builds Five-Tier C2 Across 15 Domains and 9 ASNs
Fifteen new domains. Nine IP addresses spanning six autonomous systems across four continents. Five distinct certificate-issuer fingerprints provisioned within a 45-day window. Since CTX Team's earlier coverage of the Trojan.Jumper campaign, the operator has not merely maintained an existing footprint — they have constructed a layered, multi-tier command-and-control architecture that reveals a level of infrastructure investment inconsistent with opportunistic or low-sophistication adversaries.
#GovernmentIOCf4 · i9 · d15 · u4MITRE18IndustriesGovernment
C&CMembersMay 26, 2026, 22:40 (UTC+9)One DigiCert Cert Signed 16 Malicious Binaries Across 18 Months
Sixteen distinct Windows binaries. Eight separate product personas. One DigiCert code-signing certificate — and not a single revocation in eighteen months. That is the operational core of a sustained adware and data-harvesting campaign that CTX Team has been tracking across the Ludashi (鲁大师) software ecosystem, where malware dressed as Chinese security utilities has been circulating since at least November 2024.
#TA551#FIN6#Group123#lockergoga#icedidActorsTA551 · ShathakIOCf30 · i25 · d9 · u9MITRE12
C&CMembersMay 26, 2026, 21:16 (UTC+9)AS214351 Adds 'PureCrack' Relay Node and DGA Domains in C2 Expansion
Since CTX Team's earlier coverage of this financially motivated campaign — documented then as a raw-IP beaconing operation running six malware families across a single young autonomous system — ten new files, two algorithmically generated domains, and a second command-and-control IP have surfaced. The most operationally significant addition is not another payload variant but a structural change to the hosting fabric itself: 196.251.107.104, a new node within AS214351 operated by Femo IT…
#AS214351#FemoITSolutions#Stealcv2#BazarLoader#Amadey#clipboardhijacker#bulletproofhosting#DGAdomainsIOCf20 · i3 · d2 · u5MITRE18RegionsAL · BO · CA · DE
C&CMembersMay 26, 2026, 21:02 (UTC+9)Dual-Cert Trojan VPN Pipeline Targets Food and Beverage Sector
Five Windows executables are circulating as components of a legitimate-looking VPN product — each carrying a valid-chain code-signing certificate issued to one of two shell entities, "INNOVATIVE CONNECTING PTE. LIMITED" and "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — while quietly establishing proxy-chain command-and-control infrastructure anchored in a Chengdu internet data centre.
#Barium#APT15#Cactus#ramnit#FoodBeveragesActorsBarium · Wicked SpiderIOCf10 · i18 · d23 · u3MITRE7IndustriesFood & Beverages
C&CMembersMay 26, 2026, 20:44 (UTC+9)Five Shell Companies, One Adware Campaign: DigiCert Cert Rotation Exposed
Thirty-one signed Windows binaries. Five distinct Chinese legal entities. One certificate authority. The Ludashi adware ecosystem — distributed under the guise of utility software products with names like LargeFileClean, WhaleMemory, Mem Optimization Pro, DupsClean, and CipherLock — has been running a sustained code-signing rotation strategy that goes well beyond what commodity adware operators typically invest in.
#FIN6#lockergoga#icedidActorsFIN6 · Skeleton SpiderIOCf31 · i4 · d12 · u8MITRE35
C&CMembersMay 26, 2026, 17:06 (UTC+9)Four Signed Certs, Ten IPs, One UnionPay Disguise: IcedID's Dual-Layer Evasion
Seventeen Windows executables and DLLs, all validly signed by DigiCert's Trusted G4 Code Signing chain, are circulating as system-cleaning and security utilities — and every one of them beacons to a C2 backend whose ten IP addresses present a wildcard TLS certificate issued to UnionPay International Co., Ltd. The combination is not accidental.
#icedidIOCf25 · i10 · d2 · u2MITRE46
C&CMembersMay 26, 2026, 16:51 (UTC+9)APT28 Burns Fake Cert, Hides Agent Behind Legit Vendor Signature
Two Windows executables, both signed with a freshly minted code-signing certificate issued to a shell identity called "Work Product Inc.," are circulating as a trojanized browser installer targeting the telecom sector — a signed-binary abuse chain [T1553.002] engineered to walk past execution controls before most endpoint tools have a chance to render a verdict.
#APT28#njrat#TelecommunicationsActorsAPT28 · StrontiumIOCf3 · i3 · d3 · u1MITRE6IndustriesTelecommunications
C&CMembersMay 26, 2026, 10:47 (UTC+9)Spring Dragon Hides SQL Implant in Signed Netease Emulator, Fools All 76 AV Engines
A 24-megabyte Windows executable presenting as the legitimate Netease MuMuPlayer Android emulator has cleared every antivirus engine that examined it — all 76 of them — while simultaneously triggering a YARA rule identifying byte patterns consistent with the SKIP-2.0 SQL Server authentication-bypass implant. The binary carries a valid, unrevoked DigiCert-rooted code-signing certificate issued to Netease Interactive Entertainment Pte.
#SpringDragon#wmi_ghost#EducationResearch#TechnologyActorsSpring Dragon · Lotus BlossomIOCf2 · i0 · d4 · u1MITRE4IndustriesEducation & Research · Technology
C&CMembersMay 26, 2026, 10:27 (UTC+9)Two DigiCert Certificates, 16 Malicious Binaries, Nine Months Unrevoked
Sixteen Windows executables bearing currently-valid DigiCert G4 code-signing certificates have been circulating across Chinese-language software distribution channels since at least August 2025, impersonating disk-cleaners, QQ-cleanup utilities, zip tools, and browser-guard products — a signed-binary abuse chain [T1553.002] that walks past Windows SmartScreen and suppresses the heuristic engines that most enterprise endpoints rely on.
#TA511ActorsTA511 · MAN1IOCf26 · i8 · d3 · u3MITRE4
C&CMembersMay 24, 2026, 17:57 (UTC+9)Six Shell Companies, One Builder: DigiCert Certs Fuelled 14-Month Signed-Malware Run
Thirty-four Windows executables carrying valid DigiCert Trusted G4 Code Signing certificates — each issued to a distinct Chinese company identity — have been circulating since October 2024, disguised as consumer PC-utility software: file cleaners, memory optimisers, browser protectors, and QQ-related tray applications. The signing identities rotate. The build toolchain does not.
#FIN6#TA428#lockergoga#ncctrojan#icedidActorsFIN6 · Skeleton SpiderIOCf34 · i13 · d11 · u10MITRE23
C&CMembersMay 24, 2026, 14:51 (UTC+9)APT28 Deploys Validly Signed Chrome Fake, Gets Zero Detections
A 4-megabyte Windows executable masquerading as Google Chrome is circulating with a valid, unexpired Google LLC code-signing certificate — and every one of the 76 antivirus engines that examined it returned a clean verdict. That single data point, drawn from CTX Team's analysis of a cluster attributed to APT28 (also tracked as Fancy Bear, Forest Blizzard, and approximately 17 other aliases), captures the operational logic of the entire campaign: when a binary carries a legitimate certificate…
#APT28#GovernmentActorsAPT28 · StrontiumIOCf2 · i1 · d3 · u6MITRE4IndustriesGovernment
C&CMembersMay 24, 2026, 14:38 (UTC+9)WHQL-Signed Driver Blinds EDR a Year Before Crypto Theft Wave
A 34-kilobyte Windows kernel driver — signed with a legitimate Microsoft Hardware Compatibility Publisher certificate, bearing Safetica copyright strings, and detected by exactly two of 76 antivirus engines — was quietly staged on victim systems as early as May 2025. Nearly a year later, a coordinated wave of credential stealers, clipboard hijackers, and browser wallet harvesters began appearing in the wild, all beaconing to a two-IP cluster in a small, recently allocated autonomous system.
#TA428#WizardSpider#pythonstealer#vulcanActorsTA428 · ThunderCatsIOCf25 · i3 · d1 · u9