
Forged 72-Hour Certificates Hid WarzoneRAT From All 76 AV Engines
A trojanised installer disguised as a legitimate German browser product delivered WarzoneRAT, a Winos4.0 stager, and a SQL Server authentication-bypass implant to targets across Germany, France, and Luxembourg. The entire payload set was signed with two deliberately short-lived Microsoft ID Verified certificates, achieving zero static detections while defeating most automated sandboxes through active evasion logic.
Seven Windows executables and DLLs, all signed under the name of a legitimate German digital-publishing company, arrived on VirusTotal on 23 May 2026 with a combined static detection score of zero across 76 engines. The files presented themselves as components of "t-online Browser 7," a real product distributed by Ströer Digital Publishing GmbH — complete with version strings, Mozilla Public License 2.0 copyright notices, and Authenticode signatures rooted in Microsoft's own…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read