
Old and New Certificates Both Fool Antivirus in Same Cluster
A 14-year-old VeriSign-signed Ammyy Admin RAT still slips past most antivirus engines, while a freshly DigiCert-signed 'net_updater.exe' flagged by a sandbox as the PBot stealer evades detection too. Both cases, found in the same infrastructure cluster, show signature trust — decayed or pristine — matters more than actual behaviour for detection.
A 2012-era remote-access tool still clears the majority of antivirus engines on the strength of a VeriSign signature that has technically expired but still chains to a valid root — while, on the other end of the trust spectrum, a binary carrying a fully current DigiCert code-signing chain issued this March slips past most detection under a stealer classification.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read