Skip to main content

Threats Tagged 'code-signing'

View all threats tagged with 'code-signing'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: code-signing

Threats Tagged 'code-signing'

Click on any threat for detailed analysis and mitigation recommendations

In January 2026, a new variant of the PlugX malware was observed being used in targeted attacks. Analysis suggests involvement of the UNC6384 APT group, linked to Mustang Panda, targeting government agencies in Southeast Asia. The malware uses a browser updater disguise to download and execute a malicious MSI file, leading to PlugX infection. The STATICPLUGIN downloader uses a revoked code-signing certificate from a Chinese company. The PlugX variant employs DLL sideloading and shellcode execution techniques. Its configuration is encrypted using RC4 and custom encoding. C2 servers were identified as fruitbrat[.]com and 108.165.255[.]97:443. The ongoing improvements to PlugX indicate its continued use in targeted attacks by APT groups.

Join the discussion

TamperedChef is a sophisticated global malvertising and SEO-driven campaign that delivers malicious payloads via seemingly legitimate, digitally signed installers. It leverages social engineering, malvertising, and abused code-signing certificates obtained through U. S. -registered shell companies to evade detection and increase user trust. The campaign primarily targets healthcare, construction, and manufacturing sectors, establishing persistence and deploying obfuscated JavaScript for remote access and control. Attackers may use this access for credential theft, ransomware preparation, or espionage. Although currently concentrated in the Americas, European organizations in similar sectors are at risk due to the campaign's stealth and persistence techniques. Mitigation requires enhanced scrutiny of signed applications, network monitoring for unusual JavaScript execution, and strict controls on software installation sources. Countries with significant healthcare and manufacturing industries, such as Germany, France, and the UK, are most likely to be affected. Given the medium severity rating and the complexity of exploitation, the threat is assessed as high severity for European contexts due to potential impact and stealth.

Join the discussion

The Rhysida ransomware gang, previously known as Vice Society, is conducting a sophisticated malvertising campaign using Bing ads to distribute OysterLoader malware. This malware acts as an initial access tool, establishing persistence and enabling further payload deployment, including ransomware. The gang employs code-signing certificates, including Microsoft Trusted Signing, to evade detection and increase trustworthiness of their malware. Their activity has notably increased in 2025, with over 40 certificates tracked compared to 7 in 2024. They also utilize Latrodectus malware for initial access. The campaign leverages legitimate services and advanced evasion techniques, highlighting significant resource investment and operational maturity. This threat poses a medium severity risk but can lead to severe consequences if ransomware is deployed. European organizations should be vigilant against malvertising campaigns and suspicious software downloads, especially those impersonating popular software. Mitigation requires enhanced monitoring of code-signed binaries, user awareness, and blocking malicious ad traffic.

Join the discussion

A new variant of the Odyssey infostealer for macOS has been discovered, featuring code signing, notarization, and a persistent backdoor. The malware mimics a Google Meet updater and uses a SwiftUI-based 'Technician Panel' for social engineering. It steals sensitive data, including passwords, browser information, and cryptocurrency wallet contents. The stealer now includes a second-stage payload that establishes persistence and communicates with a command-and-control server. Notable features include dynamic command execution, network tunneling capabilities, and self-termination mechanisms. The malware also employs anti-analysis techniques to evade researchers. Multiple signed and notarized samples have been identified in the wild, indicating an evolution in the threat actor's tactics.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: code-signing
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses