
Revoked 2011 Certificate Still Fools Users into Trusting AutoIt Loader
A GlobalSign code-signing certificate revoked years ago still lends a false sense of legitimacy to an AutoIt-compiled decoy that VirusTotal flags as revoked and not-time-valid. The decoy sits alongside an unsigned dropper that sandboxes identify as the NetWire RAT, both linked to a decades-old No-IP domain live-bound to a Leaseweb Germany host.
A code-signing certificate that GlobalSign revoked years ago is still doing work for its original signer's name — just not for the original signer's purpose. In a file cluster CTX Team has been tracking, a binary that presents itself as the legitimate AutoIt v3 scripting runtime carries a signature chain rooted in AutoIt Consulting Ltd, issued through GlobalSign ObjectSign CA back in May 2011 and expired by design in 2014.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read