FILE
150 stories
FILEMembersJun 28, 2026, 02:17 (UTC+9)Trojanised BitTorrent Installer Evades 74 of 75 AV Engines in 33-Country Campaign
A 4.3 MB Windows executable presenting full BitTorrent branding — product name "BT® Classic," version 51.1054.0.0, copyright "©2026 BitTorrent Limited" — is circulating as a trojanised installer that achieves a 1-in-75 detection rate while routing harvested credentials to a colocation block in Iceland whose servers answer with a *.utorrent.com TLS certificate.
#trojanisedinstaller#credentialharvesting#WebView2credentialstores#Icelandcolocationinfrastructure#CloudFrontC2#governmentandtelecomtargeting#BobSoftpacker#BitTorrentlureIOCf53 · i5 · d2 · u0MITRE70RegionsAD · AR · AT · BAIndustriesGovernment · Media · Technology
FILEPublicJun 27, 2026, 14:07 (UTC+9)ZBot Dropper Targets Italy's Food Sector in Espionage Campaign
A 191-kilobyte Windows executable named to look like a scanned document attachment has been circulating against Italian food and beverage companies, carrying a layered evasion stack that walks past automated analysis environments before injecting a PandaBanker payload into a legitimate host process. The file — submitted to VirusTotal under the name Allegato_02,Allegato_01.Tif.exe, where allegato is Italian for "attachment" — exploits the double-extension convention to make a Win32 executable…
#BambooSpider#PandaBanker#ZBot#VBInject#foodandbeveragesector#Italy#processinjection#sandboxevasionActorsBamboo SpiderIOCf2 · i0 · d0 · u0MITRE37RegionsITIndustriesFood & Beverages
FILEMembersJun 27, 2026, 10:16 (UTC+9)One Stolen Microsoft Cert Binds Four-Malware Toolkit Targeting Farms
A financially motivated operator has assembled a four-component malware toolkit — Azorult credential stealer, ClipBanker cryptocurrency hijacker, a KillAV module, and an Andromeda dropper — and stamped every piece with the same stolen or forged Microsoft Corporation code-signing certificate, serial number 33 00 00 01 87 72 17 72 15 59 40 C7 09 00 00 00 00 01 87, signing date 2020-07-20.
#Azorult#ClipBanker#Andromeda#KillAV#code-signingcertificateabuse#agriculturesector#BrazilColombiaItaly#PS2EXEIOCf9 · i2 · d0 · u2MITRE43RegionsBR · CO · ITIndustriesAgriculture
FILEMembersJun 27, 2026, 09:45 (UTC+9)Ten-Year-Old ranapama Injector Still Harvesting US Retail Credentials in 2026
A Win32 injector compiled in June 2015 and first submitted to public malware repositories that same month is running active credential-theft operations against US retail targets in 2026 — not as a curiosity or a legacy artifact, but as a functional, evasion-engineered payload routing traffic through a 51-node relay pool spanning at least ten autonomous systems across Eastern Europe, the Caucasus, and Western Europe.
#ranapama#processhollowing#credentialharvesting#USretail#sandboxevasion#LeaseWebNetherlands#EasternEuroperelayinfrastructure#packedinjectorIOCf1 · i51 · d0 · u8MITRE30RegionsUSIndustriesRetail
FILEMembersJun 27, 2026, 05:44 (UTC+9)One lolMiner Kit, Repackaged 20 Ways, Beats Static Detection
Twenty of the forty-three file indicators feeding this campaign are not independent malware samples — they are one dropped cryptomining toolkit, copied and renamed across batch scripts, shell scripts, a VBA-tagged loader pair, a ZIP archive and a single compiled Windows binary. Every one of them shares the identical directory scaffold resources/bin/lolminer/1.98a/ and duplicated install paths under %ProgramFiles%\CommonProgramFiles(x86)\microsoft shared\{bc4eaae6|71d5719f}\lolminer\1.98a\.
#lolMiner#cryptojacking#batchscriptmalware#dynamicDNSinfrastructure#unsignedbinaries#multi-coinmining#Dynu#ContabohostingIOCf43 · i2 · d2 · u2MITRE48RegionsAU · BE · BR · CAIndustriesConstruction · Media · Retail
FILEMembersJun 26, 2026, 22:27 (UTC+9)njRAT Campaign Hides C2 Behind Free Cloud Platforms for Three Years
An njRAT operator running a build pipeline that has remained functionally intact since at least February 2023 has systematically routed command-and-control traffic through Cloudflare Pages, Netlify, and Render — three free-tier hosting platforms whose shared wildcard TLS certificates make per-subdomain blocking operationally impractical without disrupting entire legitimate services.
#njRAT#Bladabindi#free-tierPaaSabuse#AES-encrypteddelivery#.NETReactor#UACbypass#DDNSinfrastructure#VietnamhostingIOCf7 · i1 · d5 · u4MITRE32RegionsUS
FILEPublicJun 26, 2026, 18:17 (UTC+9)Fake Chinese PDF App Delivers ValleyRAT to Jordan's Food Sector
A 1,649-kilobyte Windows executable named kvipgui.exe — dressed as "极光PDF" (Aurora PDF), a plausible Chinese productivity application — has been circulating as a ValleyRAT shellcode runner targeting food and beverage organisations in Jordan, according to CTX Team analysis. The binary's most immediate deception is structural: it carries a DigiCert-rooted code-signing certificate issued to Shanghai entity 茉柏枘(上海)软件科技有限公司 that expired on 30 May 2024, yet the PE timestamp reads 29 April 2024 and…
#VoidArachne#ValleyRAT#foodandbeveragesector#Jordan#code-signingcertificateabuse#shellcoderunner#C2infrastructure#sandboxevasionActorsVoid Arachne · Silver FoxIOCf2 · i1 · d0 · u0MITRE26RegionsJOIndustriesFood & Beverages
FILEMembersJun 26, 2026, 10:15 (UTC+9)A ZIP, a Batch Script, a Fake PDF Previewer: Inside a Staged Malware Chain
A cluster of 24 file indicators submitted between June 1 and June 24, 2026 traces a delivery pattern that looks less like a single tailored intrusion and more like an assembly line: an archive carrying one batch script, a MSIL loader wearing the metadata of a document-preview utility, and a separate stealer sample whose YARA hits span everything from ransomware command detection to crypto-wallet browser extension harvesting.
#AgentTesla#XWorm#commoditymalware#MSILloader#ZIParchivedelivery#browsercredentialtheft#sandboxevasion#builder-kitmalwareIOCf24 · i1 · d0 · u1MITRE38RegionsBR · EG · ES · GBIndustriesAutomotive · Consulting · Education & Research
FILEMembersJun 26, 2026, 02:43 (UTC+9)EV Certificate Held 13 Months Before Signing Four Malicious Payloads
Four Windows executables and an MSI installer, all bearing a valid Sectigo Extended Validation code-signing certificate issued to a company called "ORYON TECH LIMITED," began circulating through cracked-software distribution channels in April 2026 — but the certificate that makes them look legitimate to Windows SmartScreen and most endpoint defences was acquired more than a year before the first payload ever appeared.
#ORYONTECHLIMITED#Microleaves#Legionadware#LummaStealer#EVcertificateabuse#pay-per-install#sandboxevasion#RomaniaIOCf20 · i1 · d5 · u13MITRE29RegionsSRIndustriesRetail · Telecommunications
FILEMembersJun 25, 2026, 22:43 (UTC+9)Single Obfuscation Builder Links BAT Stager and MSIL Dropper in 19-Country Campaign
An 8-kilobyte DOS batch file and an 85-kilobyte .NET executable — separated by file type, detection rate, and apparent purpose — turn out to share a single obfuscation fingerprint that binds them into a deliberately engineered attack chain. The YARA rule SUSP_PS1_JAB_Pattern_Jun22_1, authored by Florian Roth of Nextron Systems and drawn from the Neo23x0 signature-base, co-fires on both components: the batch stager (SHA-256 02af6b5d…) and the MSIL dropper (SHA-256 d35dbfec…).
#MSILdropper#BATstager#PowerShelldownloader#Bitviseimpersonation#content-typespoofing#sandboxevasion#technologysector#multi-countrycampaignIOCf9 · i0 · d1 · u2MITRE30RegionsAT · BD · CA · CHIndustriesAgriculture · Education & Research · Media
FILEMembersJun 25, 2026, 18:28 (UTC+9)Salty Spider Hides Expiro in Adobe's Own Sandbox Temp Path
A 60-kilobyte GZIP archive, first submitted to VirusTotal on 22 March 2025, sits at the centre of an evasion architecture that has so far produced zero detections across 78 scanning engines. The file's distinguishing feature is not its contents — those remain opaque without a sandbox verdict — but where it lives: every observed submission path resolves to C:\Users\user\AppData\Local\Temp\acrocef_low\, the low-integrity process temp directory belonging to Adobe Acrobat's Chromium Embedded…
#SaltySpider#Expiro#AdobeAcrobatCEFsandbox#CDNcertificatemasquerade#AkamaiTLSspoofing#DigiRomaniaASN8708#enterpriseendpointevasion#fileinfectorActorsSalty Spider · KuKuIOCf55 · i1 · d0 · u0MITRE29
FILEMembersJun 25, 2026, 14:18 (UTC+9)Gorgon Group Wraps Commodity Stealers in Four-Layer Evasion Stack
A GZIP archive bearing the filename "RFQ Number QUO19009852.exe" is the outermost layer of a credential-theft operation that CTX Team has been tracking against Windows endpoints. The file is unremarkable at first glance — a compressed archive mimicking a supplier quotation request, the kind of attachment that moves through purchasing inboxes without triggering much suspicion.
#GorgonGroup#ponystealer#predator_pain#PEiDpacking#spear-phishing#credentialtheft#anti-forensictimestamp#procurementlureActorsGorgon Group · SubaatIOCf7 · i0 · d0 · u0MITRE41
FILEMembersJun 25, 2026, 10:07 (UTC+9)LummaStealer Campaign Hides Nine C2 Domains Behind One Server
Nine command-and-control domains provisioned in a single week in December 2025 form the backbone of an active LummaStealer campaign targeting India — and the infrastructure's construction reveals an operator who planned for partial takedown from the outset. Eight of those domains share a single self-signed TLS certificate serial and, in seven cases, a single resolving IP address, meaning the elaborate domain pool amounts to DNS-level wallpaper over one physical server.
#LummaStealer#AutoItdropper#C2infrastructure#India#credentialtheft#self-signedTLS#malware-as-a-service#infrastructurecompartmentalisationIOCf10 · i0 · d9 · u17MITRE31RegionsIN
FILEMembersJun 23, 2026, 22:05 (UTC+9)WZTeam KMS Trojan Stacks Five Evasion Layers Behind 23-Year Cert
##A 23-Year Certificate and Five Stacked Evasion Layers: Inside the WZTeam KMS Trojan Chain Three UPX-packed Windows executables presenting as KMSAuto++ activation tools have been circulating with a self-issued code-signing certificate that carries a validity window stretching to the year 2039 — a deliberate, long-lived signing identity engineered to pass casual inspection at the moment a user decides whether to run a crack.
#WZTeam#KMSAuto#Koadic#PowerShelldownloader#code-signingabuse#Mexico#Philippines#defenseevasionActorsAPT27 · TEMP.HippoIOCf9 · i1 · d0 · u2RegionsMX · PH
FILEMembersJun 23, 2026, 06:07 (UTC+9)Fake uTorrent Installers Pair Valid Code Signing With CDN Impersonation
A cluster of Windows installers dressed up as the BitTorrent and uTorrent clients is circulating alongside a supporting network layer that borrows something rarely seen in commodity adware distribution: wildcard TLS certificates minted for someone else's brand. Three unrelated hosting providers — Digi Romania S.A. (AS8708, Romania), Advania Island ehf (AS50613, Iceland), and a Singapore-registered network called ACE (AS139341) — each present certificates whose subject lines point to major CDN…
#BitTorrent#uTorrent#code-signingcertificate#CDNimpersonation#wildcardTLScertificate#CloudFront#adware#bundlewareinstallerIOCf28 · i4 · d2 · u0MITRE46RegionsBR · CA · CG · CHIndustriesEducation & Research · Technology · Telecommunications
FILEMembersJun 22, 2026, 18:33 (UTC+9)Revoked 2005 Certificate Still Delivering LSA Credential Stealer in 2026
A Windows executable bearing a webHancer Corporation code-signing certificate — issued by ThawteCode Signing CA, valid only from August 2004 to September 2005, explicitly distrusted, time-invalid, and with revocation status listed as offline — was submitted to threat intelligence platforms as recently as March 6, 2026. That single observation frames everything that follows: a multi-component bundle combining two distinct mid-2000s adware product lines, a versioned auto-update delivery mechanism…
#LSAcredentialdumper#adware-trojanhybrid#revokedcode-signingcertificate#NewDotNet#webHancer#CEDP.Stealer#telecommunicationssector#sandboxevasionIOCf16 · i2 · d2 · u4MITRE43RegionsGB · MXIndustriesTelecommunications
FILEMembersJun 22, 2026, 18:17 (UTC+9)Meteorite Downloader Delivers Azorult and OskiStealer to Media Targets
A Varist-packed dropper self-identifying as "Meteorite Downloader v3.01" has been observed targeting media organisations in Canada, France, and the United States, delivering Azorult and OskiStealer credential-theft payloads through a layered evasion stack that combines timing-based sandbox defeat, three concurrent process-injection sub-techniques, and active suppression of security tooling.
#MeteoriteDownloader#Azorult#OskiStealer#Varistpacker#mediasector#processinjection#credentialtheft#multi-clusterinfrastructureIOCf3 · i0 · d11 · u3MITRE21RegionsCA · FR · USIndustriesMedia
FILEMembersJun 21, 2026, 21:17 (UTC+9)Godzilla Loader Campaign Byte-Mutates Five Variants, Exfiltrates India Victim's Documents
Five nearly identical 9-kilobyte Windows executables are circulating as the primary delivery mechanism for a Godzilla Loader campaign whose most operationally revealing detail is not the malware itself — it is the five zero-detection text files sitting in the same dataset, each one a harvested document from a victim's own machine, packaged with a unique victim token and dual collection timestamps from July and August 2024.
#GodzillaLoader#FileGrabber#India#dataexfiltration#bytemutation#C2infrastructure#PE32loader#stealerIOCf12 · i0 · d5 · u6MITRE30RegionsIN
FILEMembersJun 21, 2026, 17:14 (UTC+9)EV-Signed Video Downloader Hides MSSQL Backdoor, Hits Zero AV Detections
Five Windows executables distributed under two consumer software brands — PPTube and iTubeGo YouTube Downloader Pro — arrived on VirusTotal between June 3 and June 6, 2026, each bearing a validly verified Sectigo Extended Validation code-signing certificate issued to an entity called "ByteHub Technology Inc." Every antivirus engine on the platform returned a clean verdict.
#Skip-2.0#MSSQLbackdoor#EVcode-signingabuse#PyArmor#telecommunicationssector#GermanySwedenThailand#ByteHubTechnologyInc#piracy-channeldeliveryIOCf28 · i1 · d2 · u1MITRE8RegionsDE · SE · THIndustriesTelecommunications
FILEMembersJun 20, 2026, 16:47 (UTC+9)APT28 Cracked-Software Lure Rode 16-Month-Old C2 Infrastructure
A single Windows executable masquerading as five popular pirated applications reached 37 independent submission sources within twelve days of its first appearance — not because the operator rushed the deployment, but because the infrastructure waiting to receive it had been quietly assembled more than a year in advance. The C2 certificate was minted in January 2025. The domains were batch-registered in April 2026. The payload surfaced in June 2026.
#APT28#Trojan.Remus/Wingo#crackedsoftwarelure#stealertrojan#C2infrastructure#sandboxevasion#credentialharvesting#UkrainehostingActorsAPT28 · StrontiumIOCf1 · i1 · d2 · u2MITRE11RegionsBD · BR · CA · CLIndustriesFood & Beverages
FILEMembersJun 20, 2026, 16:33 (UTC+9)LHA Lure Drops PureLog Stealer and XWorm With 0/76 Persistence Layer
A 935-kilobyte ZIP archive named docPO-Q-2606010-ASN _ ZBSPR26-007.PDF(849KB).LHA is circulating as a spearphishing attachment across engineering firms, retail organisations, and telecommunications providers in Bosnia-Herzegovina, Colombia, the Czech Republic, Malaysia, and the United States. The filename is a layered deception: the .LHA extension appended after a fake PDF size annotation is engineered to make the archive read as a harmless purchase-order document to a distracted procurement or…
#PureLogStealer#XWorm#spearphishingattachment#double-extensionlure#.NETReactor#DDNScommand-and-control#engineeringandtelecomsectors#SetupComplete.cmdpersistenceIOCf23 · i3 · d1 · u2MITRE60RegionsBA · CO · CZ · MYIndustriesEngineering · Retail · Telecommunications
FILEMembersJun 19, 2026, 09:13 (UTC+9)Stealc v2 Adds Chrome Encryption Bypass in Two-Stage Stealer Pivot
Twelve new files and a single Spamhaus DROP-listed IP are the visible footprint of a credential-theft operation that has materially retooled since its earlier iteration. Where prior coverage documented a SmokeLoader-based lure with multiple C2 nodes, the campaign now deploys a sequenced SVCStealer loader and Stealc v2 payload — two unsigned 64-bit Windows executables that independently check in to the same raw IPv4 address, 62.60.226.159, hosted under AS214351 (Femo IT Solutions Limited,…
#Stealcv2#SVCStealer#infostealer#Chromeapp-boundencryptionbypass#Exoduswallet#Romania#bullet-proofhosting#two-stageloaderActorsAPT28 · StrontiumIOCf31 · i1 · d0 · u1MITRE42RegionsAU
FILEMembersJun 19, 2026, 08:48 (UTC+9)Gozi Banking Trojan Routes C2 Through Trio of Tor Onion Addresses
Three algorithmically generated Tor v3 hidden-service addresses — each a 56-character base32 string indistinguishable from random noise — are currently routing bot check-ins for an active Gozi banking-trojan campaign tracked by CTX Team as CTXv7povuldk2. The addresses were not registered through any conventional registrar, carry no TLS certificates that could be fingerprinted, and leave no DNS footprint that a sinkhole could intercept.
#Gozi#ISFB#Torhiddenservices#DGA#bankingtrojan#C2infrastructure#compile-after-delivery#datadestructionIOCf24 · i0 · d3 · u1MITRE38
FILEMembersJun 19, 2026, 05:02 (UTC+9)Signed Adware Dropper Hits 39 Countries With 2/76 AV Detections
A trojanised BitComet installer bearing a commercially obtained Sectigo code-signing certificate is circulating across 39 countries, achieving a detection rate of just 2 out of 76 engines on its dropper component — not through novel exploitation or zero-day tradecraft, but through the deliberate layering of a valid certificate chain, sandbox-evasion instrumentation, and AWS CloudFront CDN abuse into what is, on the surface, a routine adware distribution campaign.
#DealPly#Offercore#code-signingabuse#sandboxevasion#adware#Chromeextensionpersistence#CDNabuse#educationsectorIOCf59 · i4 · d1 · u0MITRE48RegionsAL · BG · BR · BSIndustriesEducation & Research · Financial Services · Technology
FILEPublicJun 19, 2026, 00:42 (UTC+9)YoroTrooper's AveMaria RAT Dropper Stacks Five Evasion Layers Before C2 Contact
Since CTX Team's earlier coverage of a WarzoneRAT cluster targeting Turkish organisations, two new file indicators have surfaced alongside the same Microsoft-themed infrastructure backbone — and the tradecraft picture they reveal is considerably more elaborate than a routine IOC refresh. The primary dropper, a 668-kilobyte Win32 PE32 executable catalogued under SHA-256 69415b18aeb7e75f4843313ed5c65e09b1a2a41d73af0ce7fed40e0f2cc2b0a0, stacks five discrete anti-analysis mechanisms before it ever…
#YoroTrooper#AveMariaRAT#WarzoneRAT#UACbypass#processinjection#sandboxevasion#CentralAsia#typosquatinfrastructureActorsYoroTrooperIOCf2 · i0 · d2 · u0MITRE21
FILEPublicJun 19, 2026, 00:24 (UTC+9)10KB SystemBC Dropper Evades Both Sandboxes in Saudi Telecom Attack
##A 10-Kilobyte Ghost: How a Zero-Import SystemBC Dropper Defeated Every Sandbox Targeting Saudi Telecom A single 10-kilobyte unsigned Windows executable — compact enough to fit inside a typical email attachment header — has been identified in a campaign against telecommunications infrastructure in Saudi Arabia, carrying a technical profile that exposes a deliberate gap in how most enterprise detection pipelines are built.
#DragonForce#SystemBC#Coroxy#sandboxevasion#telecommunications#SaudiArabia#bullet-proofhosting#proxy-RATActorsDragonForce · DragonForce MalaysiaIOCf1 · i1 · d0 · u0MITRE8RegionsSAIndustriesTelecommunications
FILEPublicJun 18, 2026, 20:29 (UTC+9)AgentTesla Stealer Activates Three-Year-Old Tanzanian Domain in Single Day
On the morning of 2 June 2026, two events occurred in close enough succession to rule out coincidence. At 12:23:47 UTC, a 90-day wildcard TLS certificate was issued by Let's Encrypt — issuer CN=YR1, serial 5fe3baf35c3534571f8e352115b86a4e57b — covering every possible subdomain of hhautoinvestment.co.tz, a Tanzanian-registered domain that had sat dormant since its registration on 24 August 2023.
#AgentTesla#credentialharvesting#processhollowing#FTPexfiltration#ageddomaininfrastructure#manufacturing#healthcare#TanzaniaccTLDIOCf3 · i0 · d1 · u1MITRE47RegionsAE · DE · DK · JPIndustriesArts & Entertainment · Automotive · Business Associations
FILEMembersJun 17, 2026, 11:08 (UTC+9)Dormant Snapchat Lure Domain Wakes After 13 Months to Serve LummaStealer
A domain registered in April 2025 under the guise of a Snapchat mod APK resource sat completely inactive for thirteen months before its operator flipped a switch in May 2026: a Let's Encrypt TLS certificate was issued, six numbered Windows executables appeared at predictable paths, and a social-engineering notes file went live alongside them.
#LummaStealer#VenomRAT#QuasarRAT#credentialtheft#cryptocurrencywalletharvesting#Canada#Telegramexfiltration#domainagingIOCf9 · i0 · d1 · u8MITRE41RegionsCA
FILEMembersJun 17, 2026, 10:36 (UTC+9)GuLoader Hits EU Healthcare via Danish Temp Folder and Forged 2013 Timestamp
A 673-kilobyte Windows executable with a Polish-language filename — Zamowienie_829522.bat, meaning "Order 829522" — is the entry point for one of the more technically deliberate GuLoader campaigns CTX Team has tracked against European healthcare targets. The file is a Nullsoft Installer self-extracting archive, flagged by 49 of 77 antivirus engines under the label trojan.makoob/nsis, and it arrives carrying a PE timestamp set to Christmas Day 2013 — a date approximately eleven years before the…
#GuLoader#NSISdropper#healthcaresector#Poland#Croatia#JPEGsteganography#cPanelC2infrastructure#ransomwareprecursorIOCf16 · i1 · d2 · u2MITRE19RegionsHR · PLIndustriesHealthcare
FILEMembersJun 15, 2026, 11:35 (UTC+9)WinosStager Loader Hides Behind Chrome, Routes All C2 Through Tor
A 66,879-kilobyte Windows executable dressed as Google Chrome is circulating across chemicals, consulting, government, and manufacturing organisations in ten countries — and every byte of its command-and-control traffic flows exclusively through the Tor anonymity network to algorithmically generated .onion hidden services, leaving no clearnet address for network defenders to block, sinkhole, or pivot from.
#WinosStager#CleverSoar#TorC2#Chromeimpersonation#compile-on-host#manufacturing#government#Skip-2.0IOCf23 · i0 · d2 · u0MITRE51RegionsGU · IN · IT · MYIndustriesChemicals · Consulting · Government
FILEPublicJun 15, 2026, 11:19 (UTC+9)APT1 Freeware Lure Still Active 12 Years On, Live Cert Reveals
A 527-kilobyte Windows executable presents itself to the world as a routine archiving utility. Its internal product string reads "B1 Free Archiver Installer," its filename circulates as B1FreeArchiver_1.4.68.exe, and its copyright notice is dated 2013. None of that is what it is. Forty-three of 77 antivirus engines classify the binary as adware.catalina/downware — a trojanised installer that bundles unwanted payloads under a recognisable freeware brand — and three concurrent IDS rules confirm…
#CommentCrew#APT1#adware.catalina#freewaremasquerading#content-typespoofing#educationsector#SouthAsia#glassesmalwarefamilyActorsComment Crew · Byzantine CandorIOCf4 · i1 · d0 · u0MITRE25RegionsSAIndustriesEducation & Research
FILEPublicJun 14, 2026, 19:07 (UTC+9)Trojanized Black Myth: Wukong Launcher Delivers Rancor Trojan to Thai Users
A 457-kilobyte Windows executable named "Launcher Black Myth Wukong.exe" is circulating in Thailand, masquerading as the Steam launcher for one of 2024's most widely played game titles — and carrying a Rancor-family trojan payload that 52 of 76 antivirus engines now flag as malicious while the Zenbox sandbox returns a clean verdict at 98% confidence. The gap between those two numbers is the story: the operators behind this campaign did not rely on a single evasion trick.
#Snowglobe#AnimalFarm#Rancor#Babar#Thailand#gaminglure#sandboxevasion#espionageActorsSnowglobe · Animal FarmIOCf3 · i0 · d1 · u0MITRE21RegionsTH
FILEPublicJun 14, 2026, 14:58 (UTC+9)Dual-Certificate PCHunter Stack Hits Finance and Telecom Across 14 Nations
A VMProtect-packed, DigiCert EV-signed executable and a Microsoft WHQL-cross-signed kernel driver — both components of the PCHunter Windows inspection utility, both carrying certificates that expired years ago but were valid at the moment of signing — are circulating in active operations against financial services, technology, and telecommunications organisations across fourteen countries.
#PCHunter#RoyalRansomware#WHQLdriverabuse#VMProtect#kernel-modedriver#financialservices#code-signingevasion#espionageActorsRoyal Ransomware · Team OneIOCf3 · i0 · d0 · u0MITRE25RegionsAT · CA · CL · CNIndustriesFinancial Services · Technology · Telecommunications
FILEMembersJun 14, 2026, 03:28 (UTC+9)Thailand Telco Trojan Hides Banking Payload Inside Fake IDM Crack
Somewhere between a piracy forum and a Thai telecom workstation, a 59-kilobyte executable named IDM_6.4x_Crack_v19.7.exe is doing something its would-be users never expected: running a layered evasion gauntlet that defeats at least one automated sandbox entirely before handing off to a 12-megabyte dropper that quietly installs a banking-capable payload, establishes registry persistence, and then erases itself from disk.
#xegumumune#bankingtrojan#Thailand#telecommunications#sandboxevasion#WMIexecution#piracylure#C2infrastructureIOCf20 · i1 · d1 · u0MITRE47RegionsTHIndustriesTelecommunications
FILEMembersJun 13, 2026, 06:59 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Credential-Theft Campaign Across 7 Countries
Since CTX Team's earlier coverage of a trojanized CorelDraw crack campaign targeting Brazil, two new file samples have surfaced that confirm the operator is not winding down — they are building out. The most recent addition carries a PE compilation timestamp of 2026-05-08 and was first submitted to VirusTotal just three days later, on May 11.
#InjectorNett#PureLogs#WinRing0x64BYOVD#LOLDrivers#cryptomining#credentialtheft#AS213010#NICENICinfrastructureIOCf7 · i2 · d3 · u4MITRE58RegionsAU · BD · BR · ESIndustriesConstruction · Hospitality & Leisure · Manufacturing
FILEMembersJun 12, 2026, 22:44 (UTC+9)Sefnit C2 URI Unchanged for a Decade as Campaign Hits Thai Telecoms
A single line of HTTP traffic — gettasks.php?protocol=0&protoversion=201&o=0&p=C:%5CUsers%5Cadmin%5CAppData%5CLocal%5CTemp%5Cexplorer.exe&f=7296000 — appears identically across four command-and-control domains whose registration dates span more than a decade, from a domain created in July 2013 through to one registered in January 2024.
#Sefnit#Graftor#CeeInject#telecommunicationsservices#Thailand#processmasquerading#registrardiversification#command-and-controlinfrastructureIOCf3 · i1 · d4 · u12MITRE26RegionsTHIndustriesTelecommunications
FILEMembersJun 12, 2026, 07:28 (UTC+9)'mixseven' Affiliate Deploys Six Malware Families via Single PPI Tag
A single pay-per-install affiliate operating under the publisher tag pub=mixseven has coordinated the simultaneous deployment of at least six distinct malware families — GCleaner, SmokeLoader, PrivateLoader, Socelars, Fabookie, RedLine Stealer, FFDroider, and Glupteba — through a layered loader chain whose network infrastructure was provisioned in a single automated session in September 2021.
#mixseven#pay-per-install#GCleaner#SmokeLoader#RedLineStealer#Glupteba#credentialharvesting#PPIaffiliatenetworkActorsSmoky Spider · BariumIOCf20 · i5 · d2 · u13MITRE64
FILEMembersJun 12, 2026, 03:25 (UTC+9)Trojanized CorelDraw Crack Hits Brazil With Four-Payload Attack Chain
A trojanized CorelDraw activation archive that has reached 887 unique submitters since March 2025 is deploying a layered attack chain against Brazil's construction, hospitality, media, and retail sectors — one that combines a PureLogs credential stealer, an embedded coin-miner, a three-stage hosts-file poisoning sequence, and a Bring Your Own Vulnerable Driver (BYOVD) component borrowed from a 2008-era kernel driver.
#PureLogs#BYOVD#WinRing0x64.sys#coin-miner#Brazil#piratedsoftwaredistribution#credentialtheft#AS213010IOCf17 · i2 · d3 · u4MITRE72RegionsBRIndustriesConstruction · Hospitality & Leisure · Media
FILEPublicJun 11, 2026, 23:43 (UTC+9)WarzoneRAT Invoice Lure Layers Anti-Analysis Stack Against Turkish Targets
A 2,695-kilobyte Windows executable, packaged under the filename Invoice.exe and built inside a commercial crypter environment, carries one of the more deliberately constructed anti-analysis stacks CTX Team has documented in a commodity remote-access trojan deployment: timing-based sandbox evasion, debugger detection, reflective code loading, process injection, UAC bypass, and an aggressive indicator-removal suite — all wrapped in a TLS-encrypted C2 channel that hides behind a hostname…
#GoldEvergreen#WarzoneRAT#AveMaria#Turkey#sandboxevasion#UACbypass#invoicephishing#C2infrastructureActorsGold Evergreen · Business ClubIOCf1 · i0 · d2 · u0MITRE21RegionsTR
FILEMembersJun 11, 2026, 19:41 (UTC+9)OceanLotus Hid Denis Backdoor Behind Forged Microsoft Identity and DNS Tunnel
Two Win32 executables compiled on the same December afternoon in 2015 represent something more instructive than their age might suggest: a precisely engineered deception stack in which every layer — binary identity, code-signing posture, execution behaviour, and network communications — was designed to pass as something legitimate. Both are Denis backdoor variants attributed to OceanLotus (also tracked as APT32, Canvas Cyclone, and Bismuth).
#OceanLotus#APT32#Denisbackdoor#DNStunnelling#code-signingforgery#sandboxevasion#binarymasquerading#SoutheastAsiaespionageActorsOceanLotus · APT32IOCf2 · i0 · d2 · u0MITRE12RegionsCN
FILEMembersJun 11, 2026, 16:10 (UTC+9)2345Pinyin IME Runs Six-Year Covert Delivery Pipeline Behind Ad-Injection Cover
A Chinese-language input method editor has been quietly running a multi-tier asset-delivery pipeline on victim hosts since at least 2018 — one whose technical fingerprints look considerably more sophisticated than the advertisement injection it ostensibly exists to perform. The 2345Pinyin IME client, distributed by Shanghai 2345 Network Technology Co., Ltd.
#2345NetworkTechnology#2345Pinyin#adware#PUA#HongKong#mediasector#CDNabuse#indicatorremovalIOCf44 · i5 · d0 · u0MITRE24RegionsHKIndustriesMedia
FILEMembersJun 11, 2026, 06:43 (UTC+9)XRed RAT Hits Peru Gov With Frozen 2019 Builder, AnyDesk Lures
Three Windows executables masquerading as a Synaptics touchpad driver and AnyDesk remote-desktop installer are circulating against Peruvian government targets, carrying an XRed RAT payload whose compiled import table has not changed since at least June 2019. The same imphash — 332f7ce65ead0adfb3d35147033aabe9 — locks together samples whose first VirusTotal submissions span four years, from June 2019 through October 2023, and the campaign was still active as recently as May 2026.
#XRedRAT#DarkKomet#Peruviangovernment#FreeDNSC2#sandboxevasion#espionage#commodityRAT#LatinAmericaActorsCactus · Cactus Ransomware GroupIOCf14 · i1 · d0 · u0MITRE20RegionsPEIndustriesGovernment
FILEPublicJun 11, 2026, 02:57 (UTC+9)Trojanised KMSAuto Delivers SmokeLoader via Three-Layer Evasion Stack
A trojanised Windows activation tool distributed through a software-piracy hosting path has been confirmed as the delivery vehicle for SmokeLoader, with the full infection chain relying on a deliberately engineered evasion stack — AutoIT compilation, aPLib decompression, UPX runtime packing, and active sandbox-fingerprinting — that goes well beyond what commodity pirated-software distributors typically invest in concealment.
#SmokySpider#SmokeLoader#AutoIT#aPLib#UPXpacking#sandboxevasion#Mongolia#softwarepiracylureActorsSmoky SpiderIOCf3 · i0 · d0 · u0MITRE28RegionsMN
FILEMembersJun 11, 2026, 02:44 (UTC+9)Autodesk Licensing Agent Hijacked to Drop Coinminer via DLL Sideload
A trojanized crack package impersonating Autodesk's Network License Manager is exploiting the legitimate AdskLicensingAgent service to load attacker-controlled code — a DLL sideload [T1574.002] that turns a trusted enterprise software component into an unwitting execution vehicle. The lure is polished enough to have drawn 461 submissions from 417 unique sources since late March 2026, and the campaign's evasion layer is effective enough that one major automated sandbox rated the primary payload…
#DLLsideloading#coinminer#AutodeskNetworkLicenseManager#AS213010#Brazilcontainersandpackaging#T1574.002#sandboxevasion#ParentLock.exeIOCf13 · i2 · d2 · u0MITRE53RegionsBRIndustriesContainers & Packaging
FILEMembersJun 10, 2026, 23:07 (UTC+9)Validly Signed uTorrent Installer Hides Trojanized Adware Payload
A Windows installer carrying a fully valid BitTorrent Inc / DigiCert code-signing chain is circulating as a trojanized uTorrent Classic setup — flagged malicious by 22 of 76 antivirus engines even though every certificate check in the chain returns clean. The same build lineage produced an unsigned, PEiD-packed sibling that only 4 of 75 engines catch.
#uTorrentimpersonation#code-signingabuse#TLScertificatespoofing#adware#offercore#inoci#myqcloud.comCDNimpersonation#PUAdistributionIOCf26 · i6 · d2 · u0RegionsAE · AL · AR · ATIndustriesCommercial Services · Education & Research · Hospitality & Leisure
FILEMembersJun 10, 2026, 07:34 (UTC+9)Allaple Worm Hijacks 20 German Business Servers as Silent C2 Relays
Twenty static IP addresses, all assigned to small German businesses on Deutsche Telekom AG's T-DSL Business service, all falling within the same RIPE-registered netblock — 217.86.128.0 through 217.86.255.255, designated DTAG-STATIC02 — form the operational backbone of an Allaple worm campaign that CTX Team has tracked from February through June 2026. None of the twenty endpoints carry a single malicious detection across 91 scanning engines on VirusTotal.
#Allaple#DeutscheTelekomAS3320#compromisedSMBinfrastructure#C2relaynetwork#sandboxevasion#wormpropagation#Germanbusinessservers#retailsectortargetingIOCf41 · i29 · d0 · u0MITRE25RegionsUSIndustriesRetail
FILEMembersJun 9, 2026, 20:32 (UTC+9)TA505 Dropper Sleeps Past Sandboxes, Stages Rockloader in 24 Countries
A roughly one-megabyte JavaScript file — encoded in UTF-16 little-endian, packed by Varist, and bearing filenames that mimic business invoice PDFs — is circulating across engineering, healthcare, manufacturing, legal, technology, and telecom organisations in 24 countries, functioning as the first stage of a delivery chain that culminates in the download of a Windows executable attributed to the rockloader family.
#TA505#rockloader#JavaScriptdropper#sandboxevasion#spear-phishing#invoicelure#everycarebd.com#espionageActorsTA505 · Hive0065IOCf38 · i0 · d1 · u3RegionsAE · AT · AZ · BDIndustriesEngineering · Healthcare · Manufacturing
FILEMembersJun 9, 2026, 16:21 (UTC+9)Old Baixaki Typosquat Cluster Resurfaces via Unrelated 2026 CDN Certificate
Three subdomains built around the name of Brazil's largest freeware portal, all registered on the same day in October 2012 through PDR Ltd. d/b/a PublicDomainRegistry.com, have re-entered current threat telemetry paired with an unrelated certificate observation on a commercial Brazilian CDN more than a decade later — a pairing that illustrates how stale infrastructure and fresh re-observation timestamps can be mistaken for a live campaign if analysts don't check the dates.
#dealply#Baixakityposquat#AzionTechnologies#GlobalSigncertificate#adware/PUPdistribution#Brazil#staleIOC#VirtualDJinstallerlureIOCf7 · i2 · d3 · u1MITRE33RegionsBRIndustriesConsulting
FILEMembersJun 9, 2026, 08:22 (UTC+9)Fake 'Sanwhole' Cert Anchors Layered Crypto-Wallet Heist via Trojanised IDE
A trojanised installer impersonating the developer tool "Netpas DevStudio" has been circulating with a self-fabricated code-signing certificate — issued by and to a fictitious entity called "Sanwhole" — whose chain terminates in an untrusted root that no legitimate certificate authority ever vouched for. Three files in the bundle carry the same fraudulent signature, the same certificate serial (26 F4 9B CA 07 79 1C 96 48 EA 3D 5A EA 7F 69 37), and the same thumbprint…
#Cryptbot#EmotetGroup#code-signingabuse#cryptocurrencywallettheft#developertoollure#sandboxevasion#infostealer#DLLspoofingActorsEmotet Group · TA542IOCf30 · i0 · d1 · u2MITRE39RegionsCI
FILEPublicJun 9, 2026, 04:10 (UTC+9)Football Manager 26 Crack Hides Two-Year-Old AutoIT Kill Chain
Since CTX Team's earlier coverage of this campaign, nine additional file indicators have surfaced, deepening the tooling picture around a multi-stage infection chain that pairs trojanized game installers with a layered evasion stack that has remained structurally intact across at least two years of active operation. The newest sample — a 20.6 MB executable named fm.exe carrying Unity Technologies copyright metadata and the embedded path C:\Games\Football Manager 26\fm.exe — represents the…
#Patchwork#APT-C-09#AutoIT#XMRig#BYOVD#WinRing0#cryptomining#LOLDriversActorsPatchwork · ChinastratsIOCf18 · i0 · d0 · u0MITRE45