APTMembers
APT

Adware Operator Re-Signs Same Stale Build Across Two CAs

A twelve-file Authenticode cohort tied to 'OneBrowser' shows an operator repeatedly re-signing an eight-month-old executable under fresh certificates rather than rebuilding it. Compile timestamps stuck at 30 May 2025 sit against signing dates through early March 2026, revealing certificate churn as a distribution mechanic rather than active malware development.

Aug 1, 2026, 21:36 (UTC+9)Last seenAug 1, 2026Severity85ByCTX TeamActorAPT28StrontiumIOC64MITRE8

A twelve-file Authenticode cohort tied to a Windows browser product called "OneBrowser" shows something unusual for a piece of adware: the operator kept re-signing the same eight-month-old executable under a fresh certificate every time the previous one lapsed. The pattern surfaces in a batch of files carrying the identical certificate serial 0E F9 0B 20 6A 1B 07 82 E0 D0 FD 33 88 24 EC 42, issued under a GoGetSSL G4 CS RSA4096 chain rooted in DigiCert, with Authenticode signing dates falling…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence