FILEMembers
FILE

One Stolen Microsoft Cert Binds Four-Malware Toolkit Targeting Farms

A financially motivated operator stamped four functionally distinct malware components — Azorult, ClipBanker, a KillAV module, and an Andromeda dropper — with a single invalid Microsoft code-signing certificate. Delivered via trojanized KMSAuto pirated-software lures, the toolkit targets agriculture-sector organisations in Brazil, Colombia, and Italy, routing stolen credentials to two Netherlands-hosted C2 endpoints.

Jun 27, 2026, 10:16 (UTC+9)Last seenJun 27, 2026Severity84ByCTX TeamIOC13MITRE43RegionsBRCOIT

A financially motivated operator has assembled a four-component malware toolkit — Azorult credential stealer, ClipBanker cryptocurrency hijacker, a KillAV module, and an Andromeda dropper — and stamped every piece with the same stolen or forged Microsoft Corporation code-signing certificate, serial number 33 00 00 01 87 72 17 72 15 59 40 C7 09 00 00 00 00 01 87, signing date 2020-07-20.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence