FILE
151 stories
FILEPublicJun 9, 2026, 04:10 (UTC+9)Football Manager 26 Crack Hides Two-Year-Old AutoIT Kill Chain
Since CTX Team's earlier coverage of this campaign, nine additional file indicators have surfaced, deepening the tooling picture around a multi-stage infection chain that pairs trojanized game installers with a layered evasion stack that has remained structurally intact across at least two years of active operation. The newest sample — a 20.6 MB executable named fm.exe carrying Unity Technologies copyright metadata and the embedded path C:\Games\Football Manager 26\fm.exe — represents the…
#Patchwork#APT-C-09#AutoIT#XMRig#BYOVD#WinRing0#cryptomining#LOLDriversActorsPatchwork · ChinastratsIOCf18 · i0 · d0 · u0MITRE45
FILEMembersJun 9, 2026, 00:37 (UTC+9)Salty Spider Pairs 7-Year Loader With Fresh Phorpiex Worm to Hit Transport
##A Seven-Year Loader Meets a Zero-Day Worm: Salty Spider's Layered Evasion Campaign Targets Transportation A freshly compiled Phorpiex worm variant — PE timestamp matching its first submission date of 2026-02-09, zero prior detection history at the moment of deployment — is circulating alongside a seven-year-old MSIL/AgentB trojan that successfully convinces automated sandbox analysis it is harmless, even as 48 of 76 antivirus engines flag it as malicious. The pairing is not accidental.
#SaltySpider#Phorpiex#MSIL/AgentB#transportationsector#sandboxevasion#bulletproofhosting#USBsocialengineering#botnetC2ActorsSalty Spider · KuKuIOCf2 · i1 · d0 · u1MITRE25IndustriesTransportation
FILEMembersJun 9, 2026, 00:21 (UTC+9)Trojanized UltraSurf Proxy Rides Expired Cert Into 2026
A Win32 build of the UltraSurf/Ultrareach censorship-circumvention proxy — a tool millions have used to punch through national firewalls — is still circulating years after the code-signing certificate underpinning it expired. The leaf certificate, issued to "Ultrareach Internet Corp." and valid from June 9, 2021 to June 9, 2024, is now flagged by validators as "not time valid," yet the GlobalSign intermediate and root certificates above it in the chain remain valid through 2029 and 2030.
#UltraSurf#Ultrareach#Glupteba2#codesigningabuse#HurricaneElectricAS6939#self-signedcertificates#MuddyWater#SilentChollimaActorsMuddyWater · TEMP.ZagrosIOCf1 · i5 · d0 · u0MITRE18IndustriesEnergy
FILEMembersJun 8, 2026, 19:41 (UTC+9)PayPal Lure Fronts Three-Family Malware Stack Tied to FortiGate C2
A trojanised credential-checker masquerading as a PayPal email validation tool has been serving as the entry point for a multi-stage payload operation that deploys at least three functionally distinct malware families — all wrapped in the same ConfuserEx Mod obfuscation layer — before routing command-and-control traffic to a single Russian IP address that presents a FortiGate appliance certificate.
#Amadey#Mofksys#ConfuserEx#reflectiveloader#credentialtheft#Russia#paymentplatforms#wormIOCf12 · i1 · d0 · u3MITRE36RegionsRO
FILEMembersJun 8, 2026, 15:58 (UTC+9)Decade-Old Bundler Trojan Drops Tor-Routed MinerGate on Chemicals Workstations
A 919-kilobyte UPX-compressed Windows executable masquerading as a routine software installer is functioning as the first stage of a two-component cryptomining chain that has been circulating since at least late 2016 and remains actively observed as of mid-2026. The dropper — internally branded "Carambis Installer" and carrying a ROSTPAY LTD.
#PinchySpider#MinerGate#Carambisbundler#cryptomining#chemicalssector#TorC2#Proton66OOO#UPXpackingActorsPinchy Spider · SodinokibiIOCf3 · i6 · d0 · u0IndustriesChemicals
FILEPublicJun 6, 2026, 16:11 (UTC+9)Trojanised KMS Activators Carry Konni Espionage Implant, WinDivert Sniffer
Five trojanised Windows activation tools — distributed under the names KMSpico, KMSAuto, and AAct — carry an embedded user-mode packet-capture driver that has no legitimate place in any licensing utility. The YARA rule WinDivert_Driver fires on all five samples, and on one of them, AAct_x64.exe (sha256: db3aa782e297b2b5d9e2a1281ebb9afd416c82722c2d2a285ef94070e4cdd5d2), a second rule fires alongside it: win_konni_auto, a Malpedia-sourced signature that detects the Konni espionage implant family.
#GamaredonGroup#Konni#WinDivert#KMSpico#piracylure#defencesector#code-signingabuse#espionageActorsGamaredon Group · CTIGIOCf7 · i0 · d0 · u0MITRE6IndustriesDefense
FILEPublicJun 6, 2026, 16:00 (UTC+9)Trojanized Macro Tool Drops BroPass and RedlineStealer on Chilean Targets
A 32-kilobyte Windows executable masquerading as a macro encryption utility has become the delivery vehicle for one of the more technically deliberate credential-theft operations CTX Team has tracked against Chilean targets in recent memory. The outer wrapper — an NSIS installer named macro_encrypter.exe — drops at least two distinct stealer families onto victim machines while simultaneously executing a layered evasion stack that includes active sandbox detection, base64-encoded gzip payloads,…
#OperationSpalax#BroPass#RedlineStealer#NSISdropper#credentialtheft#Chile#sandboxevasion#code-signingabuseActorsOperation SpalaxIOCf3 · i0 · d0 · u1MITRE30RegionsCL
FILEMembersJun 6, 2026, 07:45 (UTC+9)72-Hour Microsoft Cert Turns Warp Terminal Installer Into Signed Dropper
On the morning of June 5, 2026, a trojanised installer impersonating the Warp Terminal application appeared on VirusTotal carrying a code-signing certificate that had been minted fewer than 48 hours earlier. The leaf cert — serial 33 00 01 A1 1D A4 AE AD B1 B2 1A 0F 7C 00 00 00 01 A1 1D, issued by Microsoft ID Verified CS EOC CA 04 under the subscriber identity "Denver Technologies, Inc. dba Warp" — was valid for exactly 72 hours, from June 3 to June 6, 2026.
#ephemeralcodesigning#MicrosoftTrustedSigning#ProcessHacker2#trojanisedinstaller#signedbinaryabuse#TorC2#commercialservices#supplychaindeliveryActorsRoyal Ransomware · Team OneIOCf8 · i0 · d0 · u0MITRE6IndustriesCommercial Services
FILEPublicJun 5, 2026, 12:39 (UTC+9)Emotet C2 Uses Auto-Rotating Certs and Zero-Detection Japan Node
A 143-kilobyte Word document disguised as a Windows system file sits at the entry point of a campaign targeting Canadian telecommunications organisations — but the more operationally significant story lies in what happens after that document executes. The command-and-control infrastructure behind this Emotet-attributed operation combines automated 89-day Let's Encrypt wildcard certificate rotation across operator-controlled domains with a fully undetected hosting node on SAKURA Internet's…
#Emotet#TA542#C2infrastructure#Let'sEncryptcertificateabuse#Canadiantelecommunications#SAKURAInternet#WordPresspathmimicry#phishingdocumentActorsEmotet Group · TA542IOCf3 · i1 · d2 · u3RegionsCAIndustriesTelecommunications
FILEMembersJun 5, 2026, 08:40 (UTC+9)XWorm RAT Campaign Stacks Four Evasion Layers Across 57 Countries
A ZIP archive disguised as a routine purchase-order document is the entry point for one of the more methodically constructed XWorm RAT delivery chains CTX Team has documented in recent months. The campaign — active since at least mid-May 2026 and reaching victims across 57 countries and 15 industry verticals — does not rely on any single clever trick.
#XWorm#RAT#purchaseorderlure#compile-after-delivery#sandboxevasion#LatinAmerica#financialservices#manufacturingIOCf11 · i1 · d1 · u3MITRE50RegionsAE · AT · AU · BDIndustriesArts & Entertainment · Automotive · Construction
FILEPublicJun 4, 2026, 07:55 (UTC+9)Gorgon Group's Remcos Campaign Hides Behind Three Evasion Layers and a Swiss No-Log VPN
A 131-kilobyte ZIP archive named "STATEMENT OF ACCOUNT - JULY'24.zip" is the entry point for a Remcos RAT campaign that layers three distinct anti-analysis mechanisms into its payload before beaconing to a Swiss no-log VPN node — a C2 address that was still receiving fresh TLS certificates as recently as May 2026, roughly six years after the initial payload cluster first appeared on VirusTotal.
#GorgonGroup#RemcosRAT#SmartAssemblyobfuscation#sandboxevasion#phishing#no-logVPNinfrastructure#financiallure#PEiDpackingActorsGorgon Group · SubaatIOCf6 · i1 · d0 · u1MITRE46
FILEMembersJun 3, 2026, 20:26 (UTC+9)Gaming-Cheat Lures Deploy XWorm RAT and Monero Miner in Europe
##Gaming-Cheat Lures Deliver XWorm RAT and Monero Miner to European Windows Users A campaign targeting Windows users in Germany and Poland is exploiting the appetite for gaming-cheat utilities to deliver a dual-payload combination of XWorm remote-access trojan and XMRig Monero miner — a financially motivated operation that layers sandbox evasion, debugger detection, and PE timestamp manipulation to reduce the likelihood of activation in analyst environments.
#XWorm#XMRig#gaminglure#credentialtheft#cryptomining#Germany#Poland#sandboxevasionIOCf32 · i1 · d1 · u2MITRE17RegionsDE · PL
FILEPublicJun 2, 2026, 12:47 (UTC+9)Signed Netease Emulator Files Hide MSSQL Backdoor, Fool All 76 AV Engines
Two trojanized components of Netease's MuMuPlayer Android emulator — both carrying a currently valid DigiCert code-signing certificate issued to Netease Interactive Entertainment Pte. Ltd. — have been identified embedding Skip-2.0 MSSQL authentication-bypass hooks inside legitimately signed Windows executables, achieving complete evasion across all 76 antivirus engines while routing command-and-control traffic through infrastructure that impersonates Akamai CDN.
#SpringDragon#Skip-2.0#MuMuPlayer#code-signingabuse#MSSQLbackdoor#educationandresearchsector#Akamaiimpersonation#supplychaincompromiseActorsSpring Dragon · Lotus BlossomIOCf2 · i3 · d1 · u0IndustriesEducation & Research
FILEMembersJun 2, 2026, 02:27 (UTC+9)Kimsuky Hides Guloader Behind Fake 'Brittlewort' Code-Signing Identity
A 326-kilobyte Windows executable named Zamówienie_Nr.2605011793800182.exe — Polish for "Order No." with a plausible invoice string appended — arrived in analysis pipelines on 18 May 2026 carrying a code-signing certificate issued by an entity called "Brittlewort." The name appears nowhere in any public certificate authority registry. It is self-issued, self-signed, and anchored to no trusted root.
#Kimsuky#Guloader#code-signingabuse#spear-phishing#sandboxevasion#Poland#NSISdropper#PEtimestampforgeryActorsKimsuky · Velvet ChollimaIOCf9 · i0 · d0 · u0MITRE18RegionsAU · DE · PLIndustriesAgriculture · Arts & Entertainment · Commercial Services
FILEMembersJun 2, 2026, 02:13 (UTC+9)Two EV Certificates Power Dual-Brand VPN Malware Evading Sandboxes
Seven Windows executables masquerading as legitimate VPN software — split across two distinct product families, WireVPN and VPNMaster — are circulating with valid Extended Validation code-signing certificates from two separate corporate entities, producing clean sandbox verdicts even as antivirus engines flag them at rates between 10 and 35 out of 76.
#Barium#APT15#WireVPN#VPNMaster#EVcode-signingabuse#sandboxevasion#foodandbeveragessector#trojanisedVPNsoftwareActorsBarium · Wicked SpiderIOCf15 · i8 · d25 · u3MITRE20IndustriesFood & Beverages
FILEMembersJun 1, 2026, 22:08 (UTC+9)Fake VPN Trojans Keep Two Invalid EV Certs Alive as Hosts Vanish
Seven Windows binaries circulating as fake VPN and proxy utilities are still riding on the same two Extended Validation code-signing identities they carried the last time CTX Team looked at this cluster — even though 22 domains, six IPs and three URLs have vanished from the campaign's front-end footprint since then. The payload side hasn't moved an inch: every signed sample in both families carries a leaf certificate that VirusTotal's chain validator flags as "not time valid," and every one of…
#code-signingabuse#EVcertificatereuse#WireVpn#VPNMaster#trojan.jumper#PUP#netfilterdriver#proxymalwareActorsBarium · Wicked SpiderIOCf15 · i2 · d3 · u0MITRE20IndustriesFood & Beverages
FILEMembersJun 1, 2026, 18:25 (UTC+9)XWorm Campaign Adds Bulletproof C2 Node on Freshly Registered Hosting
A new command-and-control node anchored to Freakhosting Ltd — a hosting provider whose RIPE block was allocated only on 2025-10-21 and whose organisation was registered as recently as 2026-01-22 — has been added to an ongoing XWorm RAT campaign that CTX Team has been tracking across multiple snapshots. The IP, 143.20.134.59, sits in the 143.20.134.0/24 network on ASN 215703 and carried just 3 of 91 engine detections at the time of analysis, meaning it was effectively invisible to the…
#XWorm#DarkTortilla#PureLogStealer#bulletproofhosting#dynamicDNS#manufacturingsector#purchase-orderlure#C2infrastructureIOCf11 · i1 · d0 · u1MITRE33RegionsAT · AU · BS · CAIndustriesChemicals · Commercial Services · Construction
FILEMembersJun 1, 2026, 12:10 (UTC+9)Four-Detection BAT Stager Opens Door to Czech Utilities via Bitbucket CDN
An 8-kilobyte DOS batch file that only four of 76 antivirus engines flag at submission time is the opening move in a campaign targeting Czech utilities infrastructure — and the low detection count is not an accident. The file, nott.bat, carries two YARA rule hits that expose its construction: SUSP_PS1_JAB_Pattern_Jun22_1, which detects UTF-16 and Base64-encoded PowerShell opening with a single-character variable, and Base64_Encoded_URL, which fires on embedded encoded URI strings.
#trojan.msil/jalapeno#Alien#CzechRepublic#utilitiessector#Bitbucketabuse#ZeroSSLC2#BATstager#PowerShelldownloaderIOCf15 · i2 · d0 · u0MITRE34RegionsCZIndustriesUtilities
FILEMembersJun 1, 2026, 07:20 (UTC+9)Scully Spider's 14-File Catalog Reveals a Decade of Mandatory Packing
Fourteen executable files. Six malware families spanning nearly two decades of Windows-targeting tradecraft. No shared infrastructure, no code-signing certificates, no passive DNS to pivot on — and yet a single, unmistakable operational signature runs through every destructive payload in the set: before anything reaches a victim machine, it gets packed.
#ScullySpider#TA547#UPXpacking#reflectiveDLLloading#CryptoWall#Rokku#Zloader#defenseevasionActorsScully Spider · TA547IOCf14 · i0 · d0 · u0MITRE8
FILEPublicJun 1, 2026, 01:53 (UTC+9)FUZZBUNCH Toolkit Bundles EternalBlue and DarkPulsar in Single APT40 Package
Nineteen files. One deployable directory tree. A complete offensive capability spanning SMB exploitation, kernel-level persistence, Tor-routed command-and-control, and a Python orchestration layer — all assembled from components whose PE compile timestamps span more than a decade of development. The FUZZBUNCH/ShadowBrokers toolkit now attributed in CTX Team's tracking to APT40, with healthcare flagged as the targeted sector, is not a collection of loosely related tools.
#APT40#EternalBlue#DarkPulsar#FUZZBUNCH#ShadowBrokers#healthcaresector#SMBexploitation#kernelbackdoorActorsAPT40 · MudcarpIOCf19 · i0 · d0 · u0IndustriesHealthcare
FILEMembersMay 31, 2026, 21:00 (UTC+9)APT28 Deploys 11-Year-Old Signed Kernel Driver in Layered Credential-Theft Campaign
A financially themed ZIP archive named HSBC_PAYMENT_ADVICE0293845678.zip is circulating as the opening move in a layered attack chain that deploys a signed vulnerable kernel driver first seen in 2015 alongside a freshly compiled DLL sideloading payload and an AgentTesla infostealer equipped with active sandbox-evasion logic.
#APT28#AgentTesla#BYOVD#xkpsm.sys#DLLsideloading#financialsector#credentialtheft#kerneldriverabuseActorsAPT28 · StrontiumIOCf43 · i0 · d0 · u0MITRE27RegionsAE · AT · AU · BDIndustriesConstruction · Engineering · Financial Services
FILEMembersMay 31, 2026, 18:27 (UTC+9)Trojanised BitComet Campaign Engineers 33-Engine Detection Gap via Shared Certificate
##A Certificate Hiding in Plain Sight: How a Trojanised BitComet Campaign Engineers Its Own Detection Gap Five Windows executables. Two code-signing identities. One AWS CloudFront subdomain. And a payload chain carefully tuned so that the component most likely to reach an endpoint registers a detection rate of just 2 out of 76 antivirus engines — while its outer wrapper, signed by the same certificate, flags on 35. That arithmetic is not an accident.
#DealPly#OfferCore#code-signingabuse#CDNfronting#sandboxevasion#adware#financialservices#CloudFrontIOCf58 · i4 · d1 · u0MITRE4RegionsAD · AE · AL · ARIndustriesArts & Entertainment · Education & Research · Financial Services
FILEMembersMay 31, 2026, 18:12 (UTC+9)Conduit-Signed Adware Dropper Achieved 6/54 Detections With Stomped Timestamps and C2 Victim Profiling
A 1.28 MB Windows executable signed with a then-valid Conduit Ltd. code-signing certificate achieved just 6 of 54 possible antivirus detections while concealing a compressed multi-payload bundle in a resource section registering entropy of 8.0 — the maximum possible for a randomly distributed byte stream. That single file, the entry point for a vigram-family adware campaign targeting technology-sector users in Spain, illustrates a layered evasion architecture that goes well beyond commodity…
#vigram#adware#code-signingabuse#browserhelperobject#PEtimestampstomping#Spain#technologysector#C2victimprofilingIOCf17 · i1 · d1 · u2MITRE22RegionsESIndustriesTechnology
FILEPublicMay 31, 2026, 09:27 (UTC+9)Plesk Default Certificate Exposes All Eight LummaStealer C2 Domains
Eight command-and-control domains serving an active LummaStealer campaign share a single Let's Encrypt TLS certificate whose subject common name reads admiring-poincare.37-77-150-150.plesk.page — the auto-generated Plesk control-panel hostname for the raw IP address 37.77.150.150, hosted on Proton66 OOO (ASN 198953) in Russia.
#LummaStealer#Pleskcertificatefingerprint#Proton66OOO#LOLBinimpersonation#code-signingchaingrafting#technologysectortargeting#Spain#MexicoIOCf18 · i1 · d9 · u17MITRE25RegionsES · MXIndustriesTechnology
FILEMembersMay 30, 2026, 23:44 (UTC+9)Gold Evergreen's Vidar Variant Hits Indonesia With Six-Layer Evasion Stack
A 1.41-megabyte unsigned Win32 executable, packed to near-maximum entropy and fetched silently through an Internet Explorer cache path, is at the centre of a credential-theft operation targeting Windows users in Indonesia. The payload — confirmed as a Vidar stealer variant by three independent YARA rules and a Zenbox sandbox classification of MALWARE/STEALER/TROJAN/EVADER at 100% confidence — does not simply steal and exfiltrate.
#GoldEvergreen#Vidarstealer#Arkeistealer#sandboxevasion#cryptocurrencywalletharvesting#dual-channelC2#Indonesia#credentialtheftActorsGold Evergreen · Business ClubIOCf1 · i0 · d0 · u4MITRE11RegionsID
FILEMembersMay 30, 2026, 21:27 (UTC+9)Patchwork Hides Kernel Driver and Crypto Miner in Pirated Game Crack
A 496-megabyte file masquerading as a Football Manager 2024 crack is the entry point for one of the more technically layered campaigns CTX Team has recently dissected — a multi-stage operation attributed to Patchwork that bundles a Bring-Your-Own-Vulnerable-Driver kernel exploit, a cryptocurrency miner dressed as a Windows system binary, and a persistent obfuscation pipeline, all delivered through the oldest social-engineering lure in the book: pirated software.
#Patchwork#BYOVD#WinRing0x64#XMRig#AutoIT#cryptocurrencymining#telecomsector#kernelexploitationActorsPatchwork · ChinastratsIOCf16 · i0 · d0 · u0MITRE41RegionsAU · BR · CM · ITIndustriesTelecommunications
FILEMembersMay 30, 2026, 21:15 (UTC+9)Fake Adobe Plugin Delivers Lumma Stealer and Cryptominer via Four-Layer Chain
A single typosquat domain — adobe-plugin.info — sits at the front of a payload chain that is considerably more engineered than its lure suggests. Behind the Adobe branding lies a structured, automated build pipeline producing at least four distinct malware components: a GCleaner MSIL trojan, a PEiD-packed dropper variant, a compact Nitol persistence stub, and a dual-purpose monetisation stage that runs Lumma stealer and a cryptominer simultaneously on the same compromised host.
#BlueBottle#Lummastealer#CoinMiner03#Nitol#GCleaner#typosquatting#creativeandmediasector#ZIPdropperActorsBlueBottle · Opera1erIOCf13 · i0 · d1 · u1RegionsUS
FILEMembersMay 30, 2026, 17:21 (UTC+9)XWorm RAT Hides C2 Behind Three Evasion Gates in RFQ Phishing Wave
A pair of Windows executables disguised as purchase-order documents began circulating on 7 May 2026, carrying a commodity remote-access trojan wrapped in enough evasion machinery to slip past automated analysis pipelines and arrive on victim systems with its command-and-control address still largely unknown to the industry. The campaign — tracked by CTX Team under the identifier CTXk3fv3k5gux — delivers XWorm RAT via a ZIP archive whose sole contents are a batch script named to mimic a…
#XWorm#SpyEx#procurementphishing#sandboxevasion#ip-api.comhosting-providercheck#energysector#manufacturingsector#commodityRATIOCf4 · i1 · d0 · u1MITRE40RegionsAL · AU · BD · CAIndustriesEnergy · Manufacturing · Retail
FILEMembersMay 30, 2026, 11:53 (UTC+9)Signed LummaStealer Bundle Clears 76 AV Engines With DigiCert Certificate
Five Windows executables carrying a valid, unexpired Reason Cybersecurity Inc. code-signing certificate — all signed in a single session at 08:53 AM on May 26, 2026, under DigiCert Trusted G4 certificate serial 07 8A A6 13 E0 E5 D5 AB 31 96 67 B9 3D 2B 96 73 — have been circulating as the payload core of a LummaStealer distribution campaign that achieves zero detections across 76 antivirus engines. The delivery vehicle is a trojanised uTorrent installer signed by BitTorrent Inc.
#LummaStealer#code-signingabuse#certificateevasion#uTorrentlure#CDNmasquerade#credentialtheft#scheduledtaskpersistence#DigiCertIOCf67 · i4 · d1 · u0MITRE49RegionsAE · AR · AT · AUIndustriesConsulting · Education & Research · Telecommunications
FILEMembersMay 30, 2026, 07:30 (UTC+9)Pay-Per-Install Campaign Adds CryptOne Dropper and Two C2 Domains in Nine Days
Since CTX Team's earlier coverage of this pay-per-install operation, the campaign has added ten new file indicators, stood up two freshly provisioned command-and-control domains within nine days of each other in May 2026, and introduced a raw-IP payload-delivery endpoint on a Netherlands-based host whose TLS certificate presents a deliberately misleading identity.
#pay-per-install#CryptOne#Microleavesadware#ORYONTECHLIMITED#OmegatechLTD#EVcertificateabuse#fakecrackedsoftware#NetherlandsC2infrastructureIOCf23 · i1 · d3 · u6MITRE31RegionsBR · EG · GB · PLIndustriesTechnology
FILEMembersMay 30, 2026, 01:34 (UTC+9)Frozen RAT Builder, Free DNS Alias Keep klovbot Active Since 2017
Sixteen Windows PE32 executables tied to the klovbot malware family are circulating against technology-sector targets in Moldova, and the most operationally revealing detail about the campaign is not the payload — it is the degree to which the operator has changed almost nothing since at least 2017. Three of those files carry enough metadata for deep analysis, and what that analysis surfaces is a tradecraft combination that has outlasted most of the defensive signatures written against it: an…
#klovbot#DarkKomet#XRed#dynamicDNS#Moldova#technologysector#sandboxevasion#USBspreaderIOCf16 · i1 · d0 · u0MITRE24RegionsMDIndustriesTechnology
FILEMembersMay 29, 2026, 14:42 (UTC+9)Single Sectigo EV Certificate Signs Four Malicious Payloads in One Batch
Four malicious Windows executables — spanning PE32, PE32+, and MSI formats, collectively masquerading as a legitimate system utility suite called "Advanced Windows Manager" — were signed with a single valid Sectigo Extended Validation code-signing certificate in one batch event on the morning of 23 April 2026. The certificate, issued to an entity named "ORYON TECH LIMITED" under the Sectigo Public Code Signing CA EV R36 chain (serial 21 E3 D5 C7 00 22 7E A0 2E E6 84 AF 4F 8F 88 40, thumbprint…
#ORYONTECHLIMITED#GCleaner#EvilCh/CryptOne#pay-per-install#EVcertificateabuse#code-signing#Egypt#UnitedKingdomIOCf23 · i1 · d3 · u7MITRE48RegionsEG · GBIndustriesTechnology
FILEMembersMay 29, 2026, 06:45 (UTC+9)One .NET Builder, Two Malware Families, One Turkish C2 IP
A single PE import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the forensic thread that ties together what initially appears to be two separate commodity malware campaigns. On one end sits a 239-kilobyte AgentTesla infostealer, first submitted to VirusTotal in December 2025 and confirmed malicious by all three sandboxes that analysed it.
#agenttesla#HospitalityLeisure#TechnologyIOCf21 · i1 · d0 · u1MITRE41RegionsMA · TRIndustriesHospitality & Leisure · Technology
FILEMembersMay 29, 2026, 02:45 (UTC+9)Packed .NET Stealer Hits Healthcare in 7 Countries With Sandbox-Aware Evasion
A 593-kilobyte .NET assembly, unsigned and unremarkable in appearance, has been circulating against healthcare organisations across Belgium, India, Italy, Sri Lanka, Pakistan, Tunisia, and the United States since at least March 2026. What makes it analytically interesting is not its payload — credential theft is commodity work — but the layered effort its operators invested in making sure analysts never get a clean look at it.
#HealthcareIOCf3 · i1 · d0 · u1MITRE24RegionsBE · IN · IT · LKIndustriesHealthcare
FILEMembersMay 28, 2026, 23:13 (UTC+9)Amadey Loader Hits Academic Networks Across 11 Countries via IE5 Cache
A freshly submitted Win32 executable — unsigned, just over 2 MB, first observed on VirusTotal on 2026-05-07 — is delivering a credential-harvesting payload to education and research institutions across eleven countries, using a staging chain that exploits legacy Internet Explorer cache paths, embeds a secondary payload in the binary's overlay section, and beacons home over raw HTTP to a single IPv4 address on a Seychelles-registered autonomous system that was provisioned less than nine months…
#APT28#EducationResearchActorsAPT28 · StrontiumIOCf2 · i1 · d0 · u1MITRE25RegionsBA · BO · CO · INIndustriesEducation & Research
FILEMembersMay 28, 2026, 22:59 (UTC+9)Expired 2017 Certificate Still Powers Process Hacker 2 Offensive Toolkit
Seventeen Windows executables — two main GUI binaries, a kernel-mode driver, a PE viewer, and thirteen plugin DLLs — have been assembled into a unified offensive package and are circulating with Authenticode signatures that expired in January 2017. The signing identity is "Wen Jia Liu," issued under two DigiCert certificate serials that together bind every file in the toolkit to a single developer lineage.
#RoyalRansomware#CommentCrew#glasses#prochackActorsRoyal Ransomware · Team OneIOCf19 · i0 · d0 · u0MITRE10
FILEMembersMay 28, 2026, 19:00 (UTC+9)Fake Windows DLL Targets Singapore Construction Firms in 16-Year Campaign
A 43-kilobyte Windows DLL masquerading as the operating system's own language-pack library is at the centre of an active implant chain targeting Singapore's construction sector — a toolkit that combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence into a layered evasion architecture that has remained operationally relevant from its first recorded submission in July 2010 through at least May 2026.
#GoblinPanda#avzhan#ConstructionActorsGoblin Panda · CycldekIOCf2 · i0 · d0 · u0MITRE23RegionsSGIndustriesConstruction
FILEMembersMay 28, 2026, 18:49 (UTC+9)Signed VPN Installer Trojan Targets Food and Beverage Firms
Three Windows executables — VPNMaster.exe, Startup.exe, and master_vpn-service.exe — are circulating as components of a coherent VPN product installation, each carrying a DigiCert G4 code-signing certificate issued to a Singapore-registered entity called "INNOVATIVE CONNECTING PTE. LIMITED." The certificate, serial number 0C 8F 89 21 C5 36 49 3E 67 DF 84 FB 82 23 B0 92, expired on 2 April 2026, yet the binaries remain structurally signed and continue to bypass security controls on systems that…
#Barium#APT15#Cactus#ramnit#FoodBeveragesActorsBarium · Wicked SpiderIOCf14 · i1 · d6 · u1MITRE7IndustriesFood & Beverages
FILEMembersMay 28, 2026, 14:45 (UTC+9)APT28's Three-Signer Chain Leaves Four Files at Zero Detections
Eight Windows executables. Three separate trusted signing identities. Four files sitting at zero detections across 76 antivirus engines. The campaign that CTX Team has been tracking under the RostPay/RostDown family designation is not a blunt-force intrusion operation — it is a methodical exercise in trust subversion, engineered so that the failure of any single certificate or detection rule leaves at least two other evasion layers intact.
#APT28#nitol#ghost#CommercialActorsAPT28 · StrontiumIOCf8 · i2 · d0 · u0MITRE11IndustriesCommercial Services
FILEMembersMay 28, 2026, 10:58 (UTC+9)XWorm Campaign Expands to Three-Channel C2 Fabric Across Offshore ASNs
Since CTX Team's earlier coverage of this XWorm campaign, two freshly provisioned command-and-control nodes have surfaced in RIPE NCC address space allocated in late 2025 — 158.94.209.22 under ASN 202412 (Omegatech LTD, Seychelles-registered) and 143.20.134.59 under ASN 215703 (Freakhosting Ltd, nominally UK-registered) — alongside a new dynamic DNS endpoint, jar5.ydns.eu, that carries no VirusTotal detection data at all.
#Commercial#Government#Manufacturing#Media#SupportServiceActivities#TechnologyIOCf12 · i2 · d0 · u1MITRE33RegionsAT · BE · BS · CAIndustriesCommercial Services · Government · Manufacturing
FILEMembersMay 28, 2026, 02:47 (UTC+9)KMSpico Trojan Chain Delivers LummaStealer to Kenya's Tech Sector
Four Windows executables carrying the same self-issued code-signing certificate have been circulating as KMSpico software activators for nearly a decade — and CTX Team's analysis of a recently surfaced indicator cluster shows that the same @ByELDI Certificate Authority, serial number CB C9 53 5C 7A 4B 70 DE 52 6C 01 39 FE AF 2C 9C, still binds the distribution chain today.
#LazarusGroup#lummastealer#TechnologyActorsLazarus Group · Hastati GroupIOCf17 · i1 · d0 · u0MITRE42RegionsKEIndustriesTechnology
FILEPublicMay 28, 2026, 02:32 (UTC+9)17-Year-Old Kernel Driver Powers 2026 Telecom Cryptomining Campaign
Compiled on April 16, 2026, and submitted to VirusTotal just two days later, an unsigned 2.5-megabyte Windows executable is doing something that should give pause to every security team protecting telecommunications infrastructure: it is loading a kernel driver that was signed in 2008, whose Authenticode certificate expired that same year, and whose vulnerabilities have been publicly catalogued for years — and using that driver to claw its way to ring-zero privilege before beaconing out to a…
#LazarusGroup#BYOVD#WinRing0x64#cryptomining#telecommunications#LOLDrivers#privilegeescalation#HashVaultActorsLazarus Group · Hastati GroupIOCf4 · i1 · d0 · u0MITRE31RegionsAR · BG · BR · GRIndustriesTelecommunications
FILEMembersMay 27, 2026, 10:29 (UTC+9)One Imphash, Two Malware Families: Inside a Shared .NET Builder
A purchase-order-themed spear-phishing campaign active since mid-May 2026 has delivered something more operationally revealing than its commodity tooling alone would suggest: two functionally distinct malware families — XWorm RAT and AgentTesla infostealer — sharing an identical PE import-table hash (imphash f34d5f2d4577ed6d9ceec516c1f5a744) and the same PEiD packer signature, confirming both were produced by a single .NET builder kit or shared loader stub.
#agenttesla#Automotive#Commercial#Construction#EducationResearch#EnergyIOCf9 · i1 · d0 · u1MITRE53RegionsAT · AU · BD · BEIndustriesAutomotive · Commercial Services · Construction
FILEPublicMay 27, 2026, 06:47 (UTC+9)Gamaredon Hides Credential-Stealer in Trojanized Driver Utility
A 39-megabyte Windows installer masquerading as the legitimate Easeware DriverEasy driver-update utility is circulating with a forged compile timestamp, a near-maximum-entropy resource section concealing an encrypted payload, and two Dotfuscator-obfuscated .NET implant components built in the same toolchain session — a layered evasion architecture that CTX Team has attributed to Gamaredon Group and linked to construction-sector targeting.
#GamaredonGroup#gamaredon#ConstructionActorsGamaredon Group · CTIGIOCf4 · i0 · d0 · u0MITRE27IndustriesConstruction
FILEMembersMay 27, 2026, 01:21 (UTC+9)XWorm Worm Campaign Hits 24 Countries via Spanish Quotation Lure
A 914-kilobyte Windows executable masquerading as a Spanish-language purchase-order request is circulating across 24 countries, carrying a payload combination that goes well beyond what most commodity-RAT deployments attempt: XWorm and PureLog Stealer bundled together, wrapped in a PEiD-packed binary with a .text section entropy of 7.83, and equipped with a worm-propagation module that can copy the infection to removable media without any additional operator action.
#BusinessAssociations#Chemicals#Construction#Engineering#Government#ManufacturingIOCf12 · i2 · d0 · u1MITRE32RegionsAT · BE · CA · CHIndustriesBusiness Associations · Chemicals · Construction
FILEMembersMay 27, 2026, 00:53 (UTC+9)APT28 Hides Espionage Chain Inside Piracy Activation Toolkit
Seventeen files. One freshly minted domain. A Moldovan hosting provider with a near-clean reputation score. On the surface, the package looks like something millions of Windows users have downloaded without a second thought: a piracy toolkit for activating unlicensed Microsoft software. Look past the familiar filenames and the campaign reveals something considerably more deliberate — a multi-layer espionage delivery chain attributed by CTX Team to APT28, the Russian state-aligned threat actor…
#APT28#powershell#TelecommunicationsActorsAPT28 · StrontiumIOCf17 · i1 · d1 · u0MITRE15IndustriesTelecommunications
FILEMembersMay 26, 2026, 17:21 (UTC+9)APT27's KMS Activator Hides a Five-Year Evasion Framework
Six Windows executables. A self-extracting archive dressed as a software licence tool. A private certificate authority whose validity window stretches to 31 December 2039. Taken individually, each component of this toolset could be dismissed as a grey-market activation utility — the kind of software that circulates freely in environments where Windows licences are expensive and enforcement is lax.
#APT27#expiro#GovernmentActorsAPT27 · TEMP.HippoIOCf6 · i0 · d0 · u0MITRE23IndustriesGovernment
FILEMembersMay 26, 2026, 11:35 (UTC+9)Expired UltraSurf Certificate Powers Stealthy C2 Campaign Against Finance
A UPX-packed Windows executable masquerading as the UltraSurf censorship-circumvention tool — signed with a GlobalSign-issued code-signing certificate that expired in June 2024 but still carries enough historical trust to fool the majority of the antivirus ecosystem — is being used to establish covert command-and-control tunnels toward freshly stood-up infrastructure on Hurricane Electric's network.
#MuddyWater#SilentChollima#Dalbit#hive#FinancialActorsMuddyWater · TEMP.ZagrosIOCf11 · i1 · d0 · u0IndustriesFinancial Services
FILEMembersMay 26, 2026, 11:05 (UTC+9)Vessel-Doc Phishing Campaign Adds Uncharacterised Hashes, Core Tradecraft Unchanged
A 901-kilobyte ZIP archive named MV_NATHAN_VSL_MAIN_PARTICULARS+Q88_DETAILS.zip is doing quiet work across at least thirteen countries. The file — first seen on VirusTotal on 2026-05-13 and submitted from two independent sources on the same day — carries a single embedded PE32 .NET assembly whose .text section registers entropy of 7.88, near the theoretical maximum, and declares zero imports.
#AgentTesla#APT29#MSILstealer#maritimesector#spearphishing#geolocationevasion#packed.NET#credentialtheftActorsAPT29 · MinidionisIOCf4 · i0 · d0 · u0MITRE47RegionsAU · CZ · DE · EGIndustriesEngineering · Financial Services · Manufacturing
FILEMembersMay 24, 2026, 17:57 (UTC+9)Snowglobe Backdoor Hides in GTA V Launcher to Hit Thai Telecoms
A 32-bit Windows executable named "Grand Theft Auto V Enhanced.exe" — one of four GTA V-branded filename variants circulating in this campaign — is not what it claims to be. Behind the high-recognition game title sits a Babar-family backdoor attributed to the Snowglobe actor cluster (also tracked as Animal Farm and Sig20), directed at telecommunications operators in Thailand under an espionage mandate.
#Snowglobe#babar#TelecommunicationsActorsSnowglobe · Animal FarmIOCf4 · i0 · d1 · u0MITRE21RegionsTHIndustriesTelecommunications