
Revoked Certs and a 1992 Timestamp: A Hacktool Kit That Won't Die
A 46-file batch shows mimikatz drivers still running on code-signing chains revoked over a decade ago, four Neshta samples tied to one builder's spoofed 1992 timestamp, and legitimate NirSoft password tools flagged as RATs the moment they're used for credential theft. There's no infrastructure to map — just recirculated, dual-use tradecraft.
The most striking fact in this 46-file batch isn't a new malware family — it's that the tools are old, freely available, and still working. Four driver and library builds of the open-source credential-dumping tool mimikatz, including the file hashed bd177792a573f81a96c7ca9833ab7090eb8a5ea0491d1b1381efc2a5ac3f54b0, continue to carry Benjamin Delpy's original code-signing chain years after the underlying certificates were explicitly revoked by their issuers.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read