
Signed Nmap Ncat Build Disguised as Windows Shell File
A curated eight-file malware batch includes a legitimately signed copy of Nmap's Ncat utility, valid EV certificate and all, dropped under a filename copied from a genuine Windows component. Only 2 of 76 scan engines flag it, next to four well-known ransomware families and a Zerologon exploit tool that detection engines catch far more reliably.
Eight files pulled into a single record span two decades of Windows malware, but the one that earns the headline is neither the biggest ransomware name in the batch nor the newest. It is a disguised build of Nmap's own Ncat utility (88119be028596ae376318a37d8baa146d7b2f7a97ae3acac4a73db3abeaea866), carrying a fully valid signing chain from "Insecure.Com LLC; DigiCert EV Code Signing CA (SHA2); DigiCert" — the same certificate authority chain that legitimately signs Nmap's own releases — yet…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read