
One Stolen Microsoft Cert Binds Four-Malware Toolkit Targeting Farms
A financially motivated operator stamped four functionally distinct malware components — Azorult, ClipBanker, a KillAV module, and an Andromeda dropper — with a single invalid Microsoft code-signing certificate. Delivered via trojanized KMSAuto pirated-software lures, the toolkit targets agriculture-sector organisations in Brazil, Colombia, and Italy, routing stolen credentials to two Netherlands-hosted C2 endpoints.
A financially motivated operator has assembled a four-component malware toolkit — Azorult credential stealer, ClipBanker cryptocurrency hijacker, a KillAV module, and an Andromeda dropper — and stamped every piece with the same stolen or forged Microsoft Corporation code-signing certificate, serial number 33 00 00 01 87 72 17 72 15 59 40 C7 09 00 00 00 00 01 87, signing date 2020-07-20.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read