Squiblydoo @squiblydoo.bsky.social · 17/09/2026During a fake IT vish targeting Germany, the attackers drop a signed file, currently one signed by "YOUR CHANCE j.d.o.o". The tool pulls the user's name and validates their credentials when entered. Credentials are saved for the attackers. github.security.tele... 010
Squiblydoo @squiblydoo.bsky.social · 01/07/2026FUD HijackLoader 9c0a88ea53c4e0324157542385a1d342101feb51cf7b8cf76e9441376f1f522a Signature: ELH Palkehituse OÜ C2: web-telegram[.]ug Was disguised as a Franz Messenger installer. 020
Squiblydoo @squiblydoo.bsky.social · 30/06/2026This is how I like my FUD malware: So many detections that I can't get the engines on the page. 2143baefd0b108fa1f6cfcfa3eb31d87578c6014117768f06bd8544dd02c8adf Signer:"F & P PARTNERS LIMITED" Gets payload from insharedata[.]org/check.php/api/launcher/14/payload?direct=1 000
Squiblydoo @squiblydoo.bsky.social · 27/06/2026Every time I look at the EV cert "Alabama Technology USA, LLC" I grow less confident it is legit. Used to sign Pulse Browser. "Alabama" company registered through a registered agent in New Mexico. Certificate chain includes a dummy cert (?) Image from pkilab.certgraveyard... 032
Squiblydoo @squiblydoo.bsky.social · 22/06/2026New blogpost discussing how the Cert Graveyard can be leveraged: through @magicswordio, rss feeds, database download, API. I also share statistics on the number of web requests I see each day and ways to support the Cert Graveyard.squiblydoo.blogUsing the Cert GraveyardSummary: This post shares some key ways to leverage the Cert Graveyard database. I also share statistics on Cert Graveyard usage and share options to support my work. If you aren’t familiar w… 010
Squiblydoo @squiblydoo.bsky.social · 22/06/2026FUD CastleLoader SHA256: b0a6f7afa4877eab5085d49207e26d1d2461d2d61d71a4d406e81e9f30711c5e C2: goldmanadv[.]com Right now, I open in #malcat, save the CAB file to disk, extract the CAB; ripgrep for the C2. Works but could be better, right? 1/2 100
Squiblydoo @squiblydoo.bsky.social · 08/06/2026Low detection CastleLoader signed "SOFTWARE ANALYTICS LIMITED": f50f825a64cb9c0435bc11db9225445687f8d1a44dba972a50ffa4dff600e72f They changed from EXE to MSI C2: arqeluno[.]com 000
Squiblydoo @squiblydoo.bsky.social · 22/05/2026Off-topic My favorite game studio has announced their new game: Knuckle Paradise. In their discord discord.gg/flyingoak If you could join the Discord and vote for me in the "chicken-fight-club" channel, it would be greatly appreciated. Game trailer below.discord.ggJoin the Flying Oak Games Discord Server!Official Flying Oak Games server. Makers of Knuckle Paradise, ScourgeBringer, NeuroVoider, Boo! Greedy Kid... | 3819 members 231
Squiblydoo @squiblydoo.bsky.social · 08/05/2026BlueVoyant published their analysis of the LoremIpsumLoader that I've been tweeting about. www.bluevoyant.com/b... The CertGraveyard had recorded 13 code-signing certificates, mostly Microsoft Trusted Signing certs used for the campaigns. h/t @tsnikle 020
Squiblydoo @squiblydoo.bsky.social · 07/05/2026We report certificates for revocation when they sign malware. What about before they sign malware? I've started adding certificates to Cert Graveyard that are being used to "warm" the certificate and improve it's score before being sign malware. 1/4 141
Squiblydoo @squiblydoo.bsky.social · 05/05/2026Kaspersky reports that recent files signed by EV code-signer "AVB Disc Soft, SIA" contain a backdoor. They report that the Daemon-Tools software have had a small backdoor since early April. (We've reported the certificate.) securelist.com/tr/da... 1/2securelist.comdaemon toolsTargeted by threat actors: individuals and organizations across 100+ countries and territories, with the majority of victims located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. 131
Squiblydoo @squiblydoo.bsky.social · 04/05/2026FUD #CastleLoader being distributed via malvertizing. 785ba9c42deca8cfc69f1aafb371802782d01bc8156a67c5c0d412c5fb3b4e33 C2: astroflightvision[.]com The signer, "Soft Insanity Oy" led us to find other FUD malware from November. 1/3 121
Squiblydoo @squiblydoo.bsky.social · 03/05/2026The RansomISAC published regarding "Zhengzhou 403 Network Technology Co., Ltd.", a cert we reported in 2025 after it was used to sign CobaltStrike. Their investigation seemed like a wild adventure, check it out. ransom-isac.org/blog... 1/3ransom-isac.orgDragonBreath: Dragon in the KernelA 0-day BYOVD vulnerability in dragoncore_k.sys signed by Zhengzhou 403 Network Technology, with shell company analysis, Dragon Breath APT-Q-27 attribution, and an APT31 / Wuhan Xiaoruizhi personnel nexus. 111
Squiblydoo @squiblydoo.bsky.social · 03/05/2026Update to pkilab.certgraveyard... - I originally hadn't planned for the analysis reports to be sharable, but it turned out people liked sharing them. They are now permanent. - Added P7X support, which was omitted by accident 000
Squiblydoo @squiblydoo.bsky.social · 29/04/2026We didn't know how an actor was using EV Certificates issued to Lenovo and others. We now do. From DigiCert's incident report: "the threat actor used a compromised analyst endpoint to access DigiCert's internal support portal. he threat actor was able to use this function... 1/3 130
Squiblydoo @squiblydoo.bsky.social · 24/04/2026CertGraveyard's PKI Lab is available now. Want to better understand code-signing certificates? The site allows you to extract and view certificates. The Cert Inspection tool parses out all of the bits and flags anomalies. 1/2 153
Squiblydoo @squiblydoo.bsky.social · 20/04/2026What do Lenovo, Kingston, Shuttle Inc, and Palit Microsystems have in common? EV Certificates from these companies were issued and used by a Chinese crime group, #GoldenEyeDog (#APT-Q-27)! Thanks @malwrhunterteam and @g0njxa for your contributions 1/7 2123
Squiblydoo @squiblydoo.bsky.social · 19/04/2026AnchorWallet[.]org is fake. The real place to download the wallet is Greymass[.]com. If you download the Windows app from the fake, you get a 680MB remote access tool signed by PIXEL PLAY PRIVATE LIMITED. Not an app signed by Greymass. h/t @malwrhunterteam 1/2 110
Squiblydoo @squiblydoo.bsky.social · 17/04/2026FUD CastleLoader signed "INFOTECK SOLUTIONS PRIVATE LIMITED" The 40MB exe makes it hard for detection engines to see the 1 important line of python it will execute. Short #malcat investigation though. 62a6e64a7233f4a756d01c54840ff703a620a416929d57eebc0bdac3b9ed2019 1/3 100
Reposted by SquiblydooJay Swan @sanjuanswan.bsky.social · 16/04/2026When I clicked on the "Bluesky Issues" trending link earlier today, every account in the first few scrolldowns was reposting the exact same text blaming the problem on AI. Each account was clearly inauthentic and was advertising video game material in its profile. 122
Squiblydoo @squiblydoo.bsky.social · 15/04/2026Orange Cyberdefence recently published their research on SmokedHam. We're glad to see Cert Graveyard and the code-signing certs mentioned. While CertGraveyard tracks the campaigns, we can't investigate them to their full depth (due to capacity), so this is great to see. 1/2 110
Squiblydoo @squiblydoo.bsky.social · 09/04/2026I don't know how to feel about this domain: maybedontbanplease[.]com What to do? Chat, can you help me out? (CastleLoader 4ba0d3ae41a0ae3143e8c2c3307c24b0d548593f97c79a30c0387b3d62504c31 signed "SERPENTINE SOLAR LIMITED" NSIS -> Python execution -> loads remote resource) 010
Squiblydoo @squiblydoo.bsky.social · 09/04/2026Golden Eye Dog (APT-Q-27) seems to have come back from break. We've seen 6 unique EV code-signing certs for campaigns in April already. All of these get reported and all get revoked. More about them in the thread. h/t @g0njxa, @malwrhunterteam 1/4 100
Squiblydoo @squiblydoo.bsky.social · 01/04/2026The CertGraveyard was created in 2025, but never received a proper introduction. We track abused code-signing certificates. When I created the site, we had 600 entries and now we have 2,250. See the blogpost below for a full overview. 1/3 164
Squiblydoo @squiblydoo.bsky.social · 01/04/2026We saw NovaViewer being signed with a new EV certificate "Xiamen Duohanbeiwei Network Co., Ltd". This certificate was reported and revoked before the certificate was used in a BumbleBee campaign. 6d6a861c133ff3e1aa09c8744de52413 Special thanks to @luke92881 and @g0njxa 1/4 110
Reposted by SquiblydooAndrew Couts @couts.bsky.social · 26/03/2026NEW: Yes, ICE can lie to you and to other law enforcement—and they've been doing it for decades. @telliotter.bsky.social reports: www.wired.com/story/why-ic...wired.comWhy ICE Is Allowed to Impersonate Law Enforcement“There's no accountability,” one expert tells WIRED of ICE’s ability to lie to the public. "The consequence of this is that it’s going to be a systemic harm across all law enforcement.” 516454
Squiblydoo @squiblydoo.bsky.social · 26/03/2026QuasarRAT signed by "北京谷云达吉商贸有限公司" This signer previously signed GhostRAT. Cert was revoked. They received new certificate. Revoked. New certificate. Revoked. If I didn't have a database with records, I'd think I was insane. h/t @malwrhunterteam 1/6 131
Squiblydoo @squiblydoo.bsky.social · 25/03/2026#Hijackloader "SettlePay - Billing Report.exe" signed by "广州杜倾科技有限公司" 02cbc77d52e12aea6a6c9db36c07d2eccd1af9d39b88b3802b40cb10d088b30c MB: bazaar.abuse[.]ch/sample/02cbc77d52… 000
Squiblydoo @squiblydoo.bsky.social · 24/03/2026Fake Microsoft Teams, "MTSetup_v15.3.7191.msi" signed by "Tryphena Lewis" 18c5b7a39be2f4a4b2fd45f0f273874f5efcc8751d4e592e5f2bcf6dbf781277 FUD-lite Uploaded to MalwareBazaar here bazaar.abuse[.]ch/sample/18c5b7a39b… 000
Squiblydoo @squiblydoo.bsky.social · 18/03/2026"gozofeliz4-guerrainfinita.exe" signed "ZHEJIANG WILLING FOREIGN TR CO MAKİNA TİCARET LİMİTED ŞİRKETİ" 808fa714b5308a813df21094c1f8e8b0 "gozofeliz4-guerrainfinita.exe" signed by "Lway Firmware" f13b26c2d4c8f1d536519b947c7300e0 what could go wrong C2: pinpadat[.]com 000
Squiblydoo @squiblydoo.bsky.social · 17/03/2026Reported to CertGraveyard: 143fa9567ebbccacceb58201dd85b7206fdf22882ff2cea0da994a513572f14e signed by "Mann Technologies LLC" Fake Citrix installer, FUD on VirusTotal, installs Zoho Meeting. 110
Reposted by SquiblydooMarcus Hutchins @malwaretech.com · 03/03/2026IMO the worst mistake people make trying to AI-proof their career is dropping everything to learn AI. It's like dropping out of math to study how to push calculator buttons really fast. The skill cap for AI is going to be your understanding of the underlying subject, not how good you are at prompts. 320637
Squiblydoo @squiblydoo.bsky.social · 03/03/2026"Zipmate.exe" signed by OR KAHOL LTD Cert reported for revocation. MD5: d5d411d61b089d5761838138e7eb484a Hijacks Firefox See REMnux MCP generated report in comment below. Claude opened the .NET using ILSpy and deobfuscated all the crap so I didn't have to. 1/2 100
Squiblydoo @squiblydoo.bsky.social · 03/03/2026"NotAWord.exe" signed "Astro Bright LTD" MD5: 7be1f9a968c5b1567570e12738392d7c Yet Another PDF Application (YAPA) App contains reversed and chunked domains. I'm now using Remnux MCP to generate reports for these apps and confirming the findings. 1/2 110
Squiblydoo @squiblydoo.bsky.social · 27/02/2026Ah yes, "Hubei Da'e Zhidao Food Technology Co., Ltd." is well known for their Google Chrome product. Valid cert. Will trust. 099d63e692457bfccc2cf59278ae6a268cb03964f18d0d27f536027b43c89896 h/t @g0njxa 020
Squiblydoo @squiblydoo.bsky.social · 24/02/2026"CaseArchiveViewer.exe" signed with "Flagship Promotion s. r. o." EV cert. Flagged for deploying NetSupport RAT and Vidar 8099e85c4aa05f50ff299a130dc26a67b45aed519668e8b1ee1692e0034196c2 Certificate reported. tria[.]ge/260223-z2lj3abx8f/behavio… h/t MalwareHunterTeam 010
Squiblydoo @squiblydoo.bsky.social · 22/02/2026#100DaysOfYARA - Day 15 (a little behind) I used @REMnux 's MCP, to extract a payload from an (unknown to me) malware, I'm now tracking as AxolotlLoader. I used the MCP to build a YARA rule based off of the XOR decryption function. Rule at end 1/5 172
Squiblydoo @squiblydoo.bsky.social · 12/02/2026DocSend.exe signed "Taiyuan Yuqianhan Network Technology Co., Ltd."; Certificate reported b409adb785f58f1de1cdf12e5c7c51a2 C2: 185.174.133.12 tria[.]ge/260211-2qa1ascw9d/behavio… #StealC h/t @malwrhunterteam 020
Squiblydoo @squiblydoo.bsky.social · 11/02/2026ScreenConnect as "LiveChat.msi" signed by "XRYUS TECHNOLOGIES LIMITED" C2: boriserton27[.]anondns[.]net e69c9a6742466a2770711804291f3fcf FUD fake PDF, new serial #: 705f570e89ccbbcb32b8bb304537a2e9 suspected Romcom "XRYUS TECHNOLOGIES CORPORATION" was used by RomCom 1/2 131
Squiblydoo @squiblydoo.bsky.social · 10/02/2026"document_725299d2.msi" signed by "ALTERNATIVE HOME HEALTHCARE SERVICES LLC" Loads ScreenConnect configured to connect to the domain zkyhgfvluyvjh[.]im edbb4d8d6b549ea5ec04e8a43e51d5fffad9276a52dacad8bba4ea09d9b41063 h/t @malwrhunterteam 1/2 110
Squiblydoo @squiblydoo.bsky.social · 10/02/2026"Purchase Agreement.pif" signed "HYPERBOLA TRADECOM LIMITED" a08293e23e09d53692aca4b20974f270e48c58c53532c6cc715993d24e928e35 Probably not a purchasing agreement and probably not a CrowdStrike Falcon sensor. Cert was reported for revocation h/t @malwrhunterteam 011
Reposted by SquiblydooLenny Zeltser @lennyzeltser.com · 09/02/2026The new REMnux MCP server connects AI agents to 200+ malware analysis tools on REMnux. I was surprised at the depth of investigation it delivers. Most of my time went into capturing how I approach the analysis and providing guidance to AI at the right time, so it can think and adapt as it works.zeltser.comUsing AI Agents to Analyze Malware on REMnuxTo analyze malware effectively, AI agents need practitioners' expertise and access to the analysis tools. The REMnux MCP server provides both, connecting AI to 200+ tools on REMnux with guidance on wh... 083
Squiblydoo @squiblydoo.bsky.social · 06/02/2026Zabbix resigned by "Xiamen Xinke Youxuan Software Technology Co., Ltd." 7ab39ede4268a615c04ef39b1b30cee3 Reaches out to zabbxsoftware[.]com Interesting lures: oficio20452026PCAP.exe PCAP Police Request Response.exe h/t @g0njxa 041
Squiblydoo @squiblydoo.bsky.social · 02/02/2026Fake Multibit wallet website multibit[.]info The real website, multibit[.]org, mentions that multibit was discontinued in 2017 The fake installer is signed by "Anhui Shanxian Tongxin Technology Co., Ltd." More details in thread h/t @malwrhunterteam 1/2 100
Squiblydoo @squiblydoo.bsky.social · 28/01/2026AhnLab published an analysis of a campaign observed by the CertGraveyard in December. Great to see more details. An actor using signer "CÔNG TY TNHH XB FLOW TECHNOLOGIES" leveraged a range of RMM tools and regularly contested abuse complaints. Blogpost in thread 1/2 111
Squiblydoo @squiblydoo.bsky.social · 28/01/2026Thorough analysis of AnyPDF (signed by "Lupus Tech Limited") rifteyy.org/report/a... Certificate has been reported and added to the CertGraveyard. 020
Squiblydoo @squiblydoo.bsky.social · 27/01/2026New FUD #Transferloader "Hangzhou Wenyu Technology Co., Ltd." Seems identical to the last one. Reaches out to the same domain: mstiserviceconfig[.]com 2c70e3b4af65679fc4f4c135dc1c03bd7ec2ae8065e2e5c50db3aaec0effc11f 011
Squiblydoo @squiblydoo.bsky.social · 27/01/2026The CertGraveyard is now being leveraged by MagicSword. MagicSword makes use of certificates we report and blocks them within your environment. I was really amazed by the work they do to block RMM and bad drivers. Now this further enables orgs to block malicious signers. x.com/magicswordio/s... 011
Squiblydoo @squiblydoo.bsky.social · 26/01/2026We've reached 2,000 entries in the CertGraveyard database. The 2,000th entry was "Auto Posto Silvestre Comercio de Combustiveis LTDA" (fuel sales), a certificate issued to a cybercriminal, used to target Brazil with a fake PDF "Requisitos_para_regularizar_sua_empresa.exe". 1/2 140
Squiblydoo @squiblydoo.bsky.social · 26/01/2026Does anyone know VirusTotal user "bsforvt727" (pronounced "bs for vt 727")? I feel like we could be friends, if we aren't already. They consistently leave comments and downvote stuff that I then see a day or two later. www[.]virustotal[.]com/gui/user/bsforvt727 021