New APT-Q-27 sample spotted
A new campaign has been identified utilizing a valid digital signature from a Chinese technology company that remains unrevoked. The attack chain employs a dropper that retrieves an extension-based module list from command and control infrastructure. The malicious payloads exploit DLL Side-Loading techniques through a legitimate Tencent-signed executable to achieve code execution. The infrastructure includes Google Cloud Storage and a dedicated domain for command and control operations. Multiple components have been identified including an EXE dropper, DLL loader, DAT payload, and the legitimate Tencent executable used for side-loading purposes.
AI Analysis
Technical Summary
This campaign involves a sophisticated attack chain where a valid digital signature from a Chinese technology company is exploited to bypass security controls. The attacker uses a dropper to retrieve an extension-based module list from command and control servers hosted on Google Cloud Storage and a dedicated domain (api.keensie.com). The malicious payloads achieve code execution by abusing DLL side-loading techniques via a legitimate Tencent-signed executable. Multiple components such as an EXE dropper, DLL loader, and DAT payload are involved. The campaign is attributed to the APT-Q-27 threat actor group. No CVE or patch information is provided, and no known exploits in the wild are reported.
Potential Impact
The campaign enables attackers to execute arbitrary code on targeted systems by abusing a trusted digital signature and DLL side-loading techniques. This can lead to unauthorized access, persistence, and potential data compromise. The use of legitimate Tencent-signed executables and valid signatures increases the likelihood of evading detection by security solutions. However, no direct evidence of widespread exploitation or specific affected software versions is available.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should monitor for indicators of compromise such as the domain api.keensie.com and the provided file hashes. Since the attack abuses a valid digital signature and DLL side-loading, consider implementing application whitelisting, restricting DLL search order, and monitoring for unusual use of signed executables. Review and validate digital signatures on executables and consider enhanced endpoint detection capabilities to identify side-loading behavior. No official fix or patch is currently documented for this campaign.
Indicators of Compromise
- domain: api.keensie.com
- hash: 8838df7298abf4d4312648e2ee80bdee
- hash: c0aca5dfbbfcb1c9796b3d974b1ee78b
- hash: 1d1808686dbf36138f3067c34566d627
- hash: 130fbe74fea31b30b59b071ccf22bf68
- url: http://api.keensie.com:5198/
New APT-Q-27 sample spotted
Description
A new campaign has been identified utilizing a valid digital signature from a Chinese technology company that remains unrevoked. The attack chain employs a dropper that retrieves an extension-based module list from command and control infrastructure. The malicious payloads exploit DLL Side-Loading techniques through a legitimate Tencent-signed executable to achieve code execution. The infrastructure includes Google Cloud Storage and a dedicated domain for command and control operations. Multiple components have been identified including an EXE dropper, DLL loader, DAT payload, and the legitimate Tencent executable used for side-loading purposes.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves a sophisticated attack chain where a valid digital signature from a Chinese technology company is exploited to bypass security controls. The attacker uses a dropper to retrieve an extension-based module list from command and control servers hosted on Google Cloud Storage and a dedicated domain (api.keensie.com). The malicious payloads achieve code execution by abusing DLL side-loading techniques via a legitimate Tencent-signed executable. Multiple components such as an EXE dropper, DLL loader, and DAT payload are involved. The campaign is attributed to the APT-Q-27 threat actor group. No CVE or patch information is provided, and no known exploits in the wild are reported.
Potential Impact
The campaign enables attackers to execute arbitrary code on targeted systems by abusing a trusted digital signature and DLL side-loading techniques. This can lead to unauthorized access, persistence, and potential data compromise. The use of legitimate Tencent-signed executables and valid signatures increases the likelihood of evading detection by security solutions. However, no direct evidence of widespread exploitation or specific affected software versions is available.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should monitor for indicators of compromise such as the domain api.keensie.com and the provided file hashes. Since the attack abuses a valid digital signature and DLL side-loading, consider implementing application whitelisting, restricting DLL search order, and monitoring for unusual use of signed executables. Review and validate digital signatures on executables and consider enhanced endpoint detection capabilities to identify side-loading behavior. No official fix or patch is currently documented for this campaign.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://x.com/askardyuss/status/2066859258130665974"]
- Adversary
- APT-Q-27
- Pulse Id
- 6a325eca53b232c21f5b84ff
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainapi.keensie.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash8838df7298abf4d4312648e2ee80bdee | — | |
hashc0aca5dfbbfcb1c9796b3d974b1ee78b | — | |
hash1d1808686dbf36138f3067c34566d627 | — | |
hash130fbe74fea31b30b59b071ccf22bf68 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://api.keensie.com:5198/ | — |
Threat ID: 6a32627a0b89be68880bd195
Added to database: 06/17/2026, 09:01:46 UTC
Last enriched: 06/17/2026, 09:15:10 UTC
Last updated: 07/30/2026, 05:24:06 UTC
Views: 310
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.