FILEMembers
FILE

Signed Nmap Ncat Build Disguised as Windows Shell File

A curated eight-file malware batch includes a legitimately signed copy of Nmap's Ncat utility, valid EV certificate and all, dropped under a filename copied from a genuine Windows component. Only 2 of 76 scan engines flag it, next to four well-known ransomware families and a Zerologon exploit tool that detection engines catch far more reliably.

Aug 16, 2026, 23:04 (UTC+9)Last seenAug 17, 2026Severity84ByCTX TeamActorLockbit GangDragonForceIOC9MITRE7

Eight files pulled into a single record span two decades of Windows malware, but the one that earns the headline is neither the biggest ransomware name in the batch nor the newest. It is a disguised build of Nmap's own Ncat utility (88119be028596ae376318a37d8baa146d7b2f7a97ae3acac4a73db3abeaea866), carrying a fully valid signing chain from "Insecure.Com LLC; DigiCert EV Code Signing CA (SHA2); DigiCert" — the same certificate authority chain that legitimately signs Nmap's own releases — yet…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence