FILEMembers
FILE

Adware Installer With Decade-Expired Cert Wrongly Tagged as Lazarus

An Amonetize-signed Win32 installer, circulating since 2014 under five unrelated filenames, carries a code-signing certificate that lapsed roughly ten years ago. Analysts reviewing the record say the bundleware fingerprint doesn't support the attached Lazarus Group / phandoor espionage label.

Sep 16, 2026, 06:44 (UTC+9)Last seenSep 16, 2026Severity87ByCTX TeamActorLazarus GroupHastati GroupIOC4MITRE13RegionsESVN

An adware installer first signed in January 2014 is still circulating with a code-signing certificate that has been invalid for roughly a decade — and the trust chain still resolves cleanly enough that antivirus engines are split on what to do with it. The file, publicly known under the generic name Installer.exe (c5a1140f6de397ad…), carries a signature block reading "Amonetize ltd.; Thawte Code Signing CA - G2; thawte" [T1553.002], but the leaf certificate's own status field says plainly:…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence