FILEMembers
FILE

72-Hour Microsoft Cert Turns Warp Terminal Installer Into Signed Dropper

A trojanised Warp Terminal installer carried a Microsoft-rooted certificate valid for just 72 hours, letting it pass 75 of 76 AV engines on VirusTotal. The installer dropped a packed stub to a randomised Windows system-root path and deployed the full Process Hacker 2 toolkit — signed with expired DigiCert credentials — for post-access reconnaissance routed through Tor.

Jun 6, 2026, 07:45 (UTC+9)Last seenJun 6, 2026Severity71ByCTX TeamActorRoyal RansomwareTeam OneIOC8MITRE6

On the morning of June 5, 2026, a trojanised installer impersonating the Warp Terminal application appeared on VirusTotal carrying a code-signing certificate that had been minted fewer than 48 hours earlier. The leaf cert — serial 33 00 01 A1 1D A4 AE AD B1 B2 1A 0F 7C 00 00 00 01 A1 1D, issued by Microsoft ID Verified CS EOC CA 04 under the subscriber identity "Denver Technologies, Inc. dba Warp" — was valid for exactly 72 hours, from June 3 to June 6, 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence