FILEMembers
FILE

Downloader Stalls, Then Runs on a Certificate That Already Expired

A Win32 downloader posing as reader.exe carries a VeriSign-rooted signing chain that fails time validation outright, wrapped around debugger checks and sandbox-stalling logic. YARA rules built for Operation Cloud Hopper and a dormant domain reactivated with a fresh 89-day certificate tie the sample to a patient, reuse-heavy espionage playbook rather than disposable crimeware.

Oct 1, 2026, 06:44 (UTC+9)Last seenOct 1, 2026Severity100ByCTX TeamActorRed ApolloPotassiumIOC7MITRE13RegionsJORO

A Win32 downloader submitted under the name reader.exe carries a code-signing chain that should never have verified — VeriSign infrastructure revoked and expired before the file was ever signed against it — wrapped around anti-debugging logic and a network fingerprint that ties it, by rule name, to detections built for Operation Cloud Hopper. The sample (d26dae0d8e5c23ec35e8b9cf126cded45b8096fc07560ad1c06585357921eeed) is not new tradecraft.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence