
Expired 2022 EV Timestamp Lets LockBit's IP Scanner Slip Past 74 of 76 AV Engines
A legitimate Famatech Advanced IP Scanner binary, signed and timestamped in April 2022 under an EV certificate chain that has since expired, is being distributed via a spearphishing link and evading nearly all antivirus detection in 2026. The campaign, attributed to the LockBit Gang, pairs the durable signing-chain abuse with a freshly provisioned Cloudflare-proxied C2 cluster and MediaFire CDN payload staging. Together, the three layers present as legitimate traffic to endpoint, network, and proxy controls simultaneously.
A Varist-packed Windows executable weighing just over 20 megabytes is circulating via a spearphishing link at adbuho.shop/iqoja, presenting itself as the legitimate Famatech Corp. Advanced IP Scanner installer — and walking past 74 of 76 antivirus engines in the process. The secret to that near-total evasion is not a novel obfuscation technique or a freshly minted fraudulent certificate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read