APTMembers
APT

One Expired Microsoft Cert Ties Three Amadey Dropper Stages Together

A trojanised KMS activation tool launches a layered dropper chain in which a single expired Microsoft Windows Publisher certificate — recycled across a PS2EXE KillAV binary, a native PE KillAV trojan, and an Amadey loader — binds all three payload stages to a single build pipeline. The campaign has run continuously from November 2021 through at least June 2026, routing C2 traffic to a bare Russian IP over plain HTTP to sidestep domain-based detection entirely.

Jun 10, 2026, 06:38 (UTC+9)Last seenJun 10, 2026Severity100ByCTX TeamIOC13MITRE31RegionsZW

Five Windows executables — two trojanised KMS software-activation tools, two dedicated AV-killing binaries, and a fully operational Amadey bot loader — form a tightly bound dropper chain whose most distinctive feature is not the payload at the end but the build discipline that assembles it. A single expired Microsoft Windows Publisher leaf certificate, serial 33 00 00 02 4B B2 23 0A 43 CD 03 63 62 00 00 00 00 02 4B, has been stamped across three distinct malware stages with an identical signing…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence