
APT33-Linked Downloader Wears a Dead Code-Signing Chain
A bsymem/Donoff sample keeps an expired GlassWire→Symantec→VeriSign signing chain attached even though VirusTotal flags it as failing validation. Wrapped in a compiled AutoIT binary with debugger checks and stalling tactics, it points to a phishing-flagged domain whose certificate was freshly reissued despite the domain being over a thousand days old.
A trojan tracked as bsymem — publicly also known as Donoff — ships with an entire three-tier code-signing chain still attached to the binary: GlassWire, a legitimate desktop network-monitoring vendor, sitting underneath a Symantec Class 3 SHA256 Code Signing CA certificate and a root VeriSign certificate. VirusTotal's verdict on that chain is blunt — "the digital signature of the object did not verify" — and two of the three certificates in it are separately flagged as "not time valid." The…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read