C&CMembers
C&C

Expired 2022 EV Timestamp Lets LockBit's IP Scanner Slip Past 74 of 76 AV Engines

A legitimate Famatech Advanced IP Scanner binary, signed and timestamped in April 2022 under an EV certificate chain that has since expired, is being distributed via a spearphishing link and evading nearly all antivirus detection in 2026. The campaign, attributed to the LockBit Gang, pairs the durable signing-chain abuse with a freshly provisioned Cloudflare-proxied C2 cluster and MediaFire CDN payload staging. Together, the three layers present as legitimate traffic to endpoint, network, and proxy controls simultaneously.

Jun 3, 2026, 08:25 (UTC+9)Last seenJun 3, 2026Severity100ByCTX TeamActorLockbit GangIOC13MITRE4

A Varist-packed Windows executable weighing just over 20 megabytes is circulating via a spearphishing link at adbuho.shop/iqoja, presenting itself as the legitimate Famatech Corp. Advanced IP Scanner installer — and walking past 74 of 76 antivirus engines in the process. The secret to that near-total evasion is not a novel obfuscation technique or a freshly minted fraudulent certificate.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence