
A Certificate for Every Stage: How DustSquad Weaponized Three Trust Systems
A DustSquad-tagged infrastructure set uses certificates as its core tradecraft at every stage of the kill chain: a revoked EV code-signing chain behind two adware bundlers, a three-day Microsoft-verified certificate wrapping a VPN-branded credential stealer, and cloned Akamai/Alibaba TLS certificates fronting command-and-control nodes on two continents. No single certificate event stands out; the significance is in the compounding pattern across delivery, evasion, and C2.
Two adware installers signed under a code-signing certificate that was later revoked. A VPN-branded credential stealer signed under a Microsoft-verified chain whose leaf certificate was valid for exactly three days. A pair of command-and-control nodes on two different continents, each wearing a TLS certificate cloned to look like Akamai or Alibaba Cloud.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read