
HijackLoader Hides Behind Real Zalo Code-Signing Certificate
A three-day-old malicious file shares an identical VNG GROUP JSC certificate serial with a clean, much larger legitimate-looking Zalo installer, both signed four minutes apart. Only 3 of 75 engines flagged the loader, while a matching TLS certificate serial ties the campaign's zdn.vn subdomain directly to an FPT Telecom-hosted IP.
Three days before this cluster surfaced, a file calling itself Zalo.exe carried a fully valid VNG GROUP JSC code-signing certificate — the same signing identity that legitimate builds of Vietnam's dominant chat app use — and only 3 of 75 engines flagged it. CAPE Sandbox and the crowdsourced YARA rule HijackLoaderStub, firing twice on the sample, both independently identified it as HijackLoader, a loader family that has no business hiding behind a trusted Vietnamese software publisher's…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read