FILEMembers
FILE

Revoked 2011 Certificate Still Fools Users into Trusting AutoIt Loader

A GlobalSign code-signing certificate revoked years ago still lends a false sense of legitimacy to an AutoIt-compiled decoy that VirusTotal flags as revoked and not-time-valid. The decoy sits alongside an unsigned dropper that sandboxes identify as the NetWire RAT, both linked to a decades-old No-IP domain live-bound to a Leaseweb Germany host.

Aug 30, 2026, 22:41 (UTC+9)Last seenAug 30, 2026Severity100ByCTX TeamActorLazyScripterIOC25MITRE27

A code-signing certificate that GlobalSign revoked years ago is still doing work for its original signer's name — just not for the original signer's purpose. In a file cluster CTX Team has been tracking, a binary that presents itself as the legitimate AutoIt v3 scripting runtime carries a signature chain rooted in AutoIt Consulting Ltd, issued through GlobalSign ObjectSign CA back in May 2011 and expired by design in 2014.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence