Skip to main content

Threats Tagged 'code signing abuse'

View all threats tagged with 'code signing abuse'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: code signing abuse

Threats Tagged 'code signing abuse'

Click on any threat for detailed analysis and mitigation recommendations

Threat actors are recompiling open source software, specifically the 7zip self-extracting archive stub, to embed a reflective loader that evades detection. The malicious code is inserted into the ExtractArchive function of the 7zip SFX module, making it difficult for analysts to identify since they typically focus on configuration files and embedded executables rather than the decompression stub itself. Samples are validly signed by Animated Productions, LLC and contain legitimate installers like foobar2000. The loader beacons to C2 servers, downloads DLLs, and reflectively loads encrypted payloads. Variants also abuse other open source libraries like the NSIS plugin EmbedHtml. Files feature bloated certificates and suspicious characteristics including installers wrapped within installers, requiring persistent analysis to uncover the hidden malicious functionality.

Join the discussion

Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

Join the discussion

A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

Join the discussion

A sophisticated infostealer operation was discovered masquerading as a cryptocurrency trading application called Tralert FX. The malicious MSI installer achieved only 3/52 AV detections by using a valid EV code signing certificate from a likely front company, AgilusTech LLC. The campaign has been active since June 2025, utilizing a three-module malware kit that includes system reconnaissance, keylogging, and browser credential theft capabilities. Stolen data is exfiltrated through five GitLab repositories via automated git commits on 30-minute cycles. Hardcoded credentials exposed the entire backend infrastructure, revealing over 4,100 commits, 90+ compromised hosts, and ongoing victim compromise. The operation demonstrates clear financial motivation with focus on cryptocurrency traders for account takeover. Three ProtonMail-linked GitLab accounts operate the infrastructure, assessed as a single operator or small team. The final payload is MoonPeak, a custom variant of XenoRAT.

Join the discussion

A supply chain compromise involving Daemon Tools installers distributed via the official vendor website has been identified. The attackers used valid code-signing certificates to make the trojanized installers appear legitimate and bypass security controls. These malicious packages deploy a backdoor that performs system reconnaissance, environment verification, and communicates with attacker-controlled command-and-control infrastructure. The compromise leverages trusted software delivery mechanisms to evade detection, establish persistent access, and enable remote command execution. Organizations should block related malicious infrastructure, hunt for suspicious Daemon Tools installations and network activity, verify software integrity, and implement application allowlisting. Monitoring for unusual certificate usage in software deployment is also advised. No patch or official fix information is available, and no known exploits in the wild have been reported.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: code signing abuse
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses