C&CMembers
C&C

Amadey Malware Wears Expired Microsoft Certificate, Skips DNS

Two payloads in a fresh Amadey-to-stealer delivery chain share a copy-pasted Microsoft signature block riding on a certificate that expired two years before the signing date. All C2 traffic across five IP addresses routes through the identical panel path, with no domains anywhere in the set.

Sep 10, 2026, 14:43 (UTC+9)Last seenSep 10, 2026Severity100ByCTX TeamIOC25MITRE43RegionsVN

Two payloads dropped in the same late-July 2025 build window — a 2,582 KB Windows executable and a 6,338 KB 64-bit DLL — carry an identical Microsoft code-signing chain, down to the leaf certificate's serial number, and both fail signature verification the moment a scanner actually checks the math. The certificate reads "Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010," a fully-formed three-tier chain that would pass a glance at a properties…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence