Threats Tagged 'microsoft trusted signing'
View all threats tagged with 'microsoft trusted signing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'microsoft trusted signing'
Click on any threat for detailed analysis and mitigation recommendations
The Rhysida ransomware gang, previously known as Vice Society, is conducting a sophisticated malvertising campaign using Bing ads to distribute OysterLoader malware. This malware acts as an initial access tool, establishing persistence and enabling further payload deployment, including ransomware. The gang employs code-signing certificates, including Microsoft Trusted Signing, to evade detection and increase trustworthiness of their malware. Their activity has notably increased in 2025, with over 40 certificates tracked compared to 7 in 2024. They also utilize Latrodectus malware for initial access. The campaign leverages legitimate services and advanced evasion techniques, highlighting significant resource investment and operational maturity. This threat poses a medium severity risk but can lead to severe consequences if ransomware is deployed. European organizations should be vigilant against malvertising campaigns and suspicious software downloads, especially those impersonating popular software. Mitigation requires enhanced monitoring of code-signed binaries, user awareness, and blocking malicious ad traffic. Join the discussion | AlienVault OTX General | 11/03/2025, 10:15:39 UTC Added: 11/03/2025, 10:56:13 UTC |
Showing 1 to 1 of 1 result