
Amadey Malware Wears Expired Microsoft Certificate, Skips DNS
Two payloads in a fresh Amadey-to-stealer delivery chain share a copy-pasted Microsoft signature block riding on a certificate that expired two years before the signing date. All C2 traffic across five IP addresses routes through the identical panel path, with no domains anywhere in the set.
Two payloads dropped in the same late-July 2025 build window — a 2,582 KB Windows executable and a 6,338 KB 64-bit DLL — carry an identical Microsoft code-signing chain, down to the leaf certificate's serial number, and both fail signature verification the moment a scanner actually checks the math. The certificate reads "Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010," a fully-formed three-tier chain that would pass a glance at a properties…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read