PULSE NAME
Calipology / SystemAutoUpdater - Trojanized RustDesk via Signed MSTeams Installer.
WHITE PetrP.73 2026-04-26 Modified: 2026-05-26
15
IOCs
MEDIUM VOLUME
A recent investigation has revealed that a trojanized Microsoft Teams installer, named MSTeamsSetup.exe, is being used to distribute a malicious version of the RustDesk remote access client. This executable file, masquerading as legitimate software, is signed with a fraudulent certificate issued to Zlatin Stamatov by Certum. The command-and-control (C2) domain associated with this operation, http://mon.systemautoupdater.com, resolves to an IP address of 23.27.141.44, which is hosted by EvoXT, a provider linked to previous cybercrime activities involving the GeorgeGinx/Striker investigation. The fraudulent certificate suggests possible identity deception linked to a legitimate UK brake caliper refurbishment business, http://calipology.co.uk.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (3 / 15 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0f971773c38e4b32acb121855151baa4 2026-04-26
FileHash-MD5 6d5e13c0269946a5a10390c178d8e9a5 2026-04-26
FileHash-MD5 ff8505309831284bff66a1cfd5049dac MD5 of 93aa31051cd1bac3bb2ffddb71f93330dcab9d89 2026-04-26