Sign in

Squiblydoo

@squiblydoo.bsky.social
301 followers 199 following 257 posts

Malware Analyst; creator of debloat, certReport, CertCentral.org Debloat Discord: discord.gg/dvGXKaY5qr squiblydoo.blog

PostsRepliesMedia
Squiblydoo @squiblydoo.bsky.social · 17/09/2026
During a fake IT vish targeting Germany, the attackers drop a signed file, currently one signed by "YOUR CHANCE j.d.o.o". The tool pulls the user's name and validates their credentials when entered. Credentials are saved for the attackers. github.security.tele...
010
Squiblydoo @squiblydoo.bsky.social · 01/07/2026
FUD HijackLoader 9c0a88ea53c4e0324157542385a1d342101feb51cf7b8cf76e9441376f1f522a Signature: ELH Palkehituse OÜ C2: web-telegram[.]ug Was disguised as a Franz Messenger installer.
020
Squiblydoo @squiblydoo.bsky.social · 30/06/2026
This is how I like my FUD malware: So many detections that I can't get the engines on the page. 2143baefd0b108fa1f6cfcfa3eb31d87578c6014117768f06bd8544dd02c8adf Signer:"F & P PARTNERS LIMITED" Gets payload from insharedata[.]org/check.php/api/launcher/14/payload?direct=1
000
Squiblydoo @squiblydoo.bsky.social · 27/06/2026
Every time I look at the EV cert "Alabama Technology USA, LLC" I grow less confident it is legit. Used to sign Pulse Browser. "Alabama" company registered through a registered agent in New Mexico. Certificate chain includes a dummy cert (?) Image from pkilab.certgraveyard...
032
Squiblydoo @squiblydoo.bsky.social · 22/06/2026
New blogpost discussing how the Cert Graveyard can be leveraged: through @magicswordio, rss feeds, database download, API. I also share statistics on the number of web requests I see each day and ways to support the Cert Graveyard.
squiblydoo.blog
Using the Cert Graveyard
Summary: This post shares some key ways to leverage the Cert Graveyard database. I also share statistics on Cert Graveyard usage and share options to support my work. If you aren’t familiar w…
010
Squiblydoo @squiblydoo.bsky.social · 22/06/2026
This is my bash command to extract the c2 rg -oIN "'[A-Za-z0-9+/=]{100,}'" | tr -d "'" | base64 -d | iconv -f utf-32 -t utf-8 | rg -o "https?://[^']+" The initial payload is 160MB and contains a bunch of junk text files, so this command pulls the C2 easy. 2/2
000
Squiblydoo @squiblydoo.bsky.social · 22/06/2026
FUD CastleLoader SHA256: b0a6f7afa4877eab5085d49207e26d1d2461d2d61d71a4d406e81e9f30711c5e C2: goldmanadv[.]com Right now, I open in #malcat, save the CAB file to disk, extract the CAB; ripgrep for the C2. Works but could be better, right? 1/2
100
Squiblydoo @squiblydoo.bsky.social · 08/06/2026
Low detection CastleLoader signed "SOFTWARE ANALYTICS LIMITED": f50f825a64cb9c0435bc11db9225445687f8d1a44dba972a50ffa4dff600e72f They changed from EXE to MSI C2: arqeluno[.]com
000
Squiblydoo @squiblydoo.bsky.social · 27/05/2026
We're close. I just need a few folk to step up and vote for me.
010
Squiblydoo @squiblydoo.bsky.social · 22/05/2026
Off-topic My favorite game studio has announced their new game: Knuckle Paradise. In their discord discord.gg/flyingoak If you could join the Discord and vote for me in the "chicken-fight-club" channel, it would be greatly appreciated. Game trailer below.
discord.gg
Join the Flying Oak Games Discord Server!
Official Flying Oak Games server. Makers of Knuckle Paradise, ScourgeBringer, NeuroVoider, Boo! Greedy Kid... | 3819 members
231
Squiblydoo @squiblydoo.bsky.social · 08/05/2026
BlueVoyant published their analysis of the LoremIpsumLoader that I've been tweeting about. www.bluevoyant.com/b... The CertGraveyard had recorded 13 code-signing certificates, mostly Microsoft Trusted Signing certs used for the campaigns. h/t @tsnikle
020
Squiblydoo @squiblydoo.bsky.social · 07/05/2026
We're working to get better attention on these certificates before they are used to sign malware. We're also working to better understand how these certificates are acquired. Interested in contributing? join the debloat discord: discord.gg/dvGXKaY5qr 4/4
discord.gg
debloat
Check out the debloat community on Discord - hang out with 192 other members and enjoy free voice and text chat.
010
Squiblydoo @squiblydoo.bsky.social · 07/05/2026
When/if it is used to sign malware, we'll also track these in the CertGraveyard.org database. Some recent examples were subsequently used to sign a fake RVTools installer: x.com/g0njxa/status/... Others, were used to sign CastleLoader. 3/4
110
Squiblydoo @squiblydoo.bsky.social · 07/05/2026
We're seeing these regularly though our monitoring of MalwareBazaar. Bitsight is uploading them when they are observed being dropped by GCleaner. The certificates follow patterns that we are already tracking and seeing be used for malware later. 2/4
100
Squiblydoo @squiblydoo.bsky.social · 07/05/2026
We report certificates for revocation when they sign malware. What about before they sign malware? I've started adding certificates to Cert Graveyard that are being used to "warm" the certificate and improve it's score before being sign malware. 1/4
141
Squiblydoo @squiblydoo.bsky.social · 05/05/2026
For a bit more detail, I ran one of the files through my AI analysis lab and gave it the Kaspersky report: github.com/Squiblydo... Oh hm. I guess a binary randomly having 1 VMProtected section does feel pretty suspicious (Image from malcat.) 2/2
020
Squiblydoo @squiblydoo.bsky.social · 05/05/2026
Kaspersky reports that recent files signed by EV code-signer "AVB Disc Soft, SIA" contain a backdoor. They report that the Daemon-Tools software have had a small backdoor since early April. (We've reported the certificate.) securelist.com/tr/da... 1/2
securelist.com
daemon tools
Targeted by threat actors: individuals and organizations across 100+ countries and territories, with the majority of victims located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
131
Squiblydoo @squiblydoo.bsky.social · 04/05/2026
CryptoCharger/CryptoVisa reaches out to 666777228[.]com which has been used by other payloads too. Notably Signer:"TRUST & SIGN POLAND SP Z O O" 045f583cb7f46ae38ea65fc25d4c7678f306a589ab599dda7d9da404ee91d2f9 which we reported in March 2026. 3/3
000
Squiblydoo @squiblydoo.bsky.social · 04/05/2026
In November "Soft Insanity Oy" received a code-signing certificate from Certum and GoGetSSL. The Certum cert signed CastleLoader, but what about the GoGetSSL? "CryptoChanger.exe" / "node.exe" a54f626f130c36709857215122d6ceb16e5fab7047316afc31a83dfa620cf292 2/3
110
Squiblydoo @squiblydoo.bsky.social · 04/05/2026
FUD #CastleLoader being distributed via malvertizing. 785ba9c42deca8cfc69f1aafb371802782d01bc8156a67c5c0d412c5fb3b4e33 C2: astroflightvision[.]com The signer, "Soft Insanity Oy" led us to find other FUD malware from November. 1/3
121
Squiblydoo @squiblydoo.bsky.social · 03/05/2026
Relatedly, I added functionality to PKILab to extract and highlight the Authenticode Publisher for Windows Hardware drivers. I had hardly noticed these details before, so I'm glad PKILab can make it easy to find. 3/3
000
Squiblydoo @squiblydoo.bsky.social · 03/05/2026
We see so many abused certificates, that we can't dig deep. If ya'll ever want to get in on the front lines of it, be sure to join the Debloat Discord where we monitor and chat about abused certificates. 2/3
100
Squiblydoo @squiblydoo.bsky.social · 03/05/2026
The RansomISAC published regarding "Zhengzhou 403 Network Technology Co., Ltd.", a cert we reported in 2025 after it was used to sign CobaltStrike. Their investigation seemed like a wild adventure, check it out. ransom-isac.org/blog... 1/3
ransom-isac.org
DragonBreath: Dragon in the Kernel
A 0-day BYOVD vulnerability in dragoncore_k.sys signed by Zhengzhou 403 Network Technology, with shell company analysis, Dragon Breath APT-Q-27 attribution, and an APT31 / Wuhan Xiaoruizhi personnel nexus.
111
Squiblydoo @squiblydoo.bsky.social · 03/05/2026
Update to pkilab.certgraveyard... - I originally hadn't planned for the analysis reports to be sharable, but it turned out people liked sharing them. They are now permanent. - Added P7X support, which was omitted by accident
000
Squiblydoo @squiblydoo.bsky.social · 29/04/2026
Special thanks goes to the regular contributors to the Cert Graveyard Also special thanks to DigiCert: this report has a high level of transparency, which is warranted, and also well executed. 3/3
000
Squiblydoo @squiblydoo.bsky.social · 29/04/2026
to access initialization codes for orders..." "Possession of the initialization code, combined with an approved order, is functionally sufficient to generate and retrieve the corresponding certificate." The full report is here bugzilla.mozilla.org/show_bug.cgi... 2/3
bugzilla.mozilla.org
2033170 - DigiCert: Misissued code signing certificates
ASSIGNED (dcbugzillaresponse) in CA Program - CA Certificate Compliance. Last updated 2026-04-28.
110
Squiblydoo @squiblydoo.bsky.social · 29/04/2026
We didn't know how an actor was using EV Certificates issued to Lenovo and others. We now do. From DigiCert's incident report: "the threat actor used a compromised analyst endpoint to access DigiCert's internal support portal. he threat actor was able to use this function... 1/3
130
Squiblydoo @squiblydoo.bsky.social · 24/04/2026
The lab is openly accessible here: pkilab.certgraveyard... I'd love to get your feedback or hear if you have any problems. :) Certificates are extracted client-side, allowing you to parse certs from 900MB+ size files. 2/2
010
Squiblydoo @squiblydoo.bsky.social · 24/04/2026
CertGraveyard's PKI Lab is available now. Want to better understand code-signing certificates? The site allows you to extract and view certificates. The Cert Inspection tool parses out all of the bits and flags anomalies. 1/2
153
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
Use CertGraveyard.org to get a list of hashes for the 69 ZhongStealer hashes. When we come to understand how they are obtaining the certificates, we'll share here. Until then, we'll continue working with the CA to mitigate the harm. 7/7
000
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
If you want a more in-depth analysis and indicators, Claude and I have been cooking: First stage analysis: github.com/Squiblydo... Second stage: github.com/Squiblydo... We have a directory of other Zhong Stealer analysis, tools, WIP bot emulator: github.com/Squiblydo... 6/7
github.com
Remnux_Reports/Zhong-Stealer-APT-Q-27/4d8c02745ed4c2bcd9bdb425d5763ebd1e6da459c1877fe9d0005e477622aa6a_photo0418699.com_analysis_report.md at main · Squiblydoo/Remnux_Reports
This repository is for reports generated by Claude and the Remnux MCP. - Squiblydoo/Remnux_Reports
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
One recent first stage was signed "Xiamen Xianghe Information Technology Co., Ltd." The second stage consists of the following: NvBackend.exe used the leaked 2018 Nvidia cert. detoured.dll was the Lenovo signed binary. NvBackend.log is a shellcode loader 5/7
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
The name Zhong Stealer seems to be a misnomer. Based on my analysis, it seems to be a RAT. They send a fake image/screenshot in a phishing email. When ran by a user, it displays a JPEG of an error, and pulls down the second stage from a CDN like AWS. 4/7
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
These certificates are unlike the other 2,100 we've tracked. They are new certificates issued to existing customers and only used to sign malware. To be clear, they aren't supply chain poisoning. We've seen 12 issued like this, 69 for this same malware: Zhong Stealer 3/7
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
First things: Each of these were mitigated. The issuing Cert Authorities were quick to act when notified. No, I don't understand how these are getting issued and abused. GoldenEyeDog seems to have unrestrained ability to create them. There may be unknown ones. 2/7
100
Squiblydoo @squiblydoo.bsky.social · 20/04/2026
What do Lenovo, Kingston, Shuttle Inc, and Palit Microsystems have in common? EV Certificates from these companies were issued and used by a Chinese crime group, #GoldenEyeDog (#APT-Q-27)! Thanks @malwrhunterteam and @g0njxa for your contributions 1/7
2123
Squiblydoo @squiblydoo.bsky.social · 19/04/2026
VirusTotal's maximum size is 650MB; potential victims can't upload it there. The certificate has been reported and revoked. A subcomponent of the file was uploaded to VirusTotal: b531ee0e453c6a514daa09a4e7d6e8fae8f433269afba59035d84e68a5ff42a2. MB: bazaar.abuse.ch/samp... 2/2
010
Squiblydoo @squiblydoo.bsky.social · 19/04/2026
AnchorWallet[.]org is fake. The real place to download the wallet is Greymass[.]com. If you download the Windows app from the fake, you get a 680MB remote access tool signed by PIXEL PLAY PRIVATE LIMITED. Not an app signed by Greymass. h/t @malwrhunterteam 1/2
110
Squiblydoo @squiblydoo.bsky.social · 17/04/2026
There is garbage text and then some Python. Highlight the base64. Right-click -> Transform. Cyberchef like interface; base64 decode, change text encoding. "Open in New file" lets us open it in a separate analysis. Theres our C2: fillenmore[.]com bazaar.abuse.ch/samp... 3/3
000
Squiblydoo @squiblydoo.bsky.social · 17/04/2026
Opening it up in malcat, we can see it identified the compressed Nullsoft Installer bits (Image 1). Double clicking unpacks it. We then have new files to look at. A few are .txt files, we can doubleclick to open them. This first one actually happens to be what we want. 2/3
100
Squiblydoo @squiblydoo.bsky.social · 17/04/2026
FUD CastleLoader signed "INFOTECK SOLUTIONS PRIVATE LIMITED" The 40MB exe makes it hard for detection engines to see the 1 important line of python it will execute. Short #malcat investigation though. 62a6e64a7233f4a756d01c54840ff703a620a416929d57eebc0bdac3b9ed2019 1/3
100
Reposted by Squiblydoo
Jay Swan @sanjuanswan.bsky.social · 16/04/2026
When I clicked on the "Bluesky Issues" trending link earlier today, every account in the first few scrolldowns was reposting the exact same text blaming the problem on AI. Each account was clearly inauthentic and was advertising video game material in its profile.
122
Squiblydoo @squiblydoo.bsky.social · 15/04/2026
The full report can be found here and is well worth the read. research.cert.orange... 2/2
000
Squiblydoo @squiblydoo.bsky.social · 15/04/2026
Orange Cyberdefence recently published their research on SmokedHam. We're glad to see Cert Graveyard and the code-signing certs mentioned. While CertGraveyard tracks the campaigns, we can't investigate them to their full depth (due to capacity), so this is great to see. 1/2
110
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
I don't know how to feel about this domain: maybedontbanplease[.]com What to do? Chat, can you help me out? (CastleLoader 4ba0d3ae41a0ae3143e8c2c3307c24b0d548593f97c79a30c0387b3d62504c31 signed "SERPENTINE SOLAR LIMITED" NSIS -> Python execution -> loads remote resource)
010
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
These are just a small subset of what we track. Over time, we've tracked 91 certificates we associate with Golden eye dog; signing both Zhong Stealer and ValleyRAT. You can get the whole list of certs from CertGraveyard's lookup page. 4/4
000
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
These are the signer's we've reported in April: Xiamen Liuyong Information Technology Co., Ltd. Xiamen Dahonghuo Technology Co., Ltd. Beijing 263 Enterprise Correspondence Co., Ltd. MobSoft Co., Ltd 深圳市优品投资顾问有限公司 Brunner Informatik AG 3/4
100
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
The main malware we're seeing via CertGraveyard is tracked as Zhong Stealer. They host the 2nd stage on legitimate CDN, one of the files they host is a picture of a 505 error this is used as a decoy. 2/4
100
Squiblydoo @squiblydoo.bsky.social · 09/04/2026
Golden Eye Dog (APT-Q-27) seems to have come back from break. We've seen 6 unique EV code-signing certs for campaigns in April already. All of these get reported and all get revoked. More about them in the thread. h/t @g0njxa, @malwrhunterteam 1/4
100
Squiblydoo @squiblydoo.bsky.social · 01/04/2026
Special thanks @abuse_ch for making MalwareBazaar available, so that we can easily find signed malware. Thank you official partners for your support and tools: @unpacme Malcat dev @magicswordio 3/3
020