Alpha Cyber

Signed to Deceive: The Return of FiveSys Rootkits

How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits.

Alpha Cyber Research1 min readupdated 1 Apr 2026
FiveSys Rootkit

Digitally-Signed Rootkits are Back – A Look at FiveSys and Companions

How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It

In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits. One standout example: FiveSys, a rootkit signed with legitimate digital certificates, has reemerged alongside a growing family of stealthy, persistent threats.

At Alpha Cyber, we’ve mapped the infrastructure supporting these threats and what we found is alarming:

Infrastructure Map Overview:

Multiple C2 servers routed through anonymizing layers
Code-signing certificates abused from legitimate vendors
Shared tooling and payload patterns across companion malware
Geotargeting tactics to focus attacks on specific regions
Persistent mechanisms that survive reboots and evade traditional AV

These aren’t just random infections, they’re highly targeted, stealth operations with the backing of well-resourced adversaries.

Why It Matters to You:

If your organization relies solely on conventional endpoint protection, you’re at serious risk. Digitally-signed rootkits like FiveSys are designed to slip through unnoticed. Once embedded, they provide full kernel-level access, ideal for espionage, data exfiltration, and sabotage.

IOCS to Block:

  • Angdao[.]com[.]cn
  • www[.]newsensation.com[.]cn

Our Response:

We offer advanced threat detection, infrastructure mapping, and threat hunting services to:
Detect rootkits and kernel-level intrusions
Reverse-engineer attacker infrastructure
Proactively hunt for related IOCs and malware variants

Protect your systems before they’re compromised.
Contact us today for a custom threat assessment or schedule a consultation.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]