← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Calipology / SystemAutoUpdater - Trojanized RustDesk via Signed MSTeams Installer.
A recent investigation has revealed that a trojanized Microsoft Teams installer, named MSTeamsSetup.exe, is being used to distribute a malicious version of the RustDesk remote access client. This executable file, masquerading as legitimate software, is signed with a fraudulent certificate issued to Zlatin Stamatov by Certum. The command-and-control (C2) domain associated with this operation, http://mon.systemautoupdater.com, resolves to an IP address of 23.27.141.44, which is hosted by EvoXT, a provider linked to previous cybercrime activities involving the GeorgeGinx/Striker investigation. The fraudulent certificate suggests possible identity deception linked to a legitimate UK brake caliper refurbishment business, http://calipology.co.uk.
Indicators of Compromise (15)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 0f971773c38e4b32acb121855151baa4 | — | 2026-04-26 | |
| FileHash-MD5 | 6d5e13c0269946a5a10390c178d8e9a5 | — | 2026-04-26 | |
| FileHash-MD5 | ff8505309831284bff66a1cfd5049dac | MD5 of 93aa31051cd1bac3bb2ffddb71f93330dcab9d89 | 2026-04-26 | |
| FileHash-SHA1 | 93aa31051cd1bac3bb2ffddb71f93330dcab9d89 | — | 2026-04-26 | |
| FileHash-SHA256 | 0c8bb17a1c27a39817f4e1bd74b6c616fba3faef909f94772e685e64fe34cef3 | — | 2026-04-26 | |
| FileHash-SHA256 | d01148808fbeefa22cd4541cdaaee8bc1f74e3045302115dc5b08b99ff93dc9c | SHA256 of 93aa31051cd1bac3bb2ffddb71f93330dcab9d89 | 2026-04-26 | |
| URL | http://23.27.141.44:443 | — | 2026-04-26 | |
| URL | https://calipology.co.uk | — | 2026-04-26 | |
| domain | calipology.co.uk | — | 2026-04-26 | |
| domain | calipology.com | — | 2026-04-26 | |
| domain | evoxt.com | — | 2026-04-26 | |
| domain | systemautoupdater.com | — | 2026-04-26 | |
| abuse@evoxt.com | — | 2026-04-26 | ||
| hostname | mon.systemautoupdater.com | — | 2026-04-26 | |
| hostname | www.calipology.com | — | 2026-04-26 |