
Kimsuky Hides Trojan in Npcap Installer With Valid Nmap Certificate
A Kimsuky-linked campaign weaponised a legitimate Nmap Software LLC code-signing certificate to deliver a trojanised Npcap OEM installer bearing a US Navy lure string. Appended overlay payloads and Windows driver-store filename masquerading combine to achieve zero detections across 76 antivirus engines. The certificate, issued in July 2024 and held unused for nearly two years, remains valid through June 2027.
A Nullsoft NSIS self-extracting installer bearing the filename npcap-1.88-oem-usnavy-testcopy-poexcu.exe — signed with a fully valid Nmap Software LLC code-signing certificate and scoring zero detections across 76 antivirus engines — represents one of the more deliberate evasion constructions CTX Team has documented in recent months.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read