Skip to main content

Threats Tagged 'digital signature'

View all threats tagged with 'digital signature'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: digital signature

Threats Tagged 'digital signature'

Click on any threat for detailed analysis and mitigation recommendations

A supply chain attack targeted the eScan antivirus software, distributing malware through the update server. The attack, detected on January 20, involved a malicious Reload.exe file that initiated a multi-stage infection chain. This malware prevented further antivirus updates, ensured persistence through scheduled tasks, and communicated with control servers to download additional payloads. Attackers gained unauthorized access to a regional update server, deploying a malicious file with a fake digital signature.eScan developers quickly isolated the affected infrastructure and reset access credentials. Users are advised to check for infection signs, use a provided removal utility, and block known malware control server addresses. Kaspersky's security solutions successfully detect the malware used in this attack.

Join the discussion

Between December 19-22, 2025, EmEditor's official website suffered a security breach, causing the main download button to serve malicious software. The fake installer, signed by WALSHAM INVESTMENTS LIMITED, contained infostealer malware targeting login credentials, browser history, and VPN settings. It specifically targeted technical staff and government offices, stealing files and installing a fraudulent browser extension for remote control and cryptocurrency address swapping. Users who downloaded during this period are advised to check the digital signature, delete suspicious files, and change stored passwords. Emurasoft is investigating the incident and has apologized for the inconvenience.

Join the discussion

A threat actor campaign observed in late 2023 and early 2024 targeted multiple regions, initially in the Far East and later Sweden, using DLL sideloading techniques combined with the Minhook library to intercept Windows API calls. The attackers leveraged compromised digital signatures, including an expired signature from a Korean game developer, to sign components and evade detection. The final payload deployed was Cobalt Strike, a known post-exploitation tool. Three distinct sideloading scenarios were identified: MiracastView, PrintDialog, and SystemSettings. The clean loader used in the attack was sourced from infected systems rather than bundled with the sideloading package, complicating detection. Indicators include multiple file hashes and suspicious domains. This campaign demonstrates sophisticated use of API hooking and sideloading to maintain persistence and evade security controls, posing a medium severity risk to affected organizations, especially in Sweden.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: digital signature
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses