APTMembers
APT

Kimsuky Hides Trojan in Npcap Installer With Valid Nmap Certificate

A Kimsuky-linked campaign weaponised a legitimate Nmap Software LLC code-signing certificate to deliver a trojanised Npcap OEM installer bearing a US Navy lure string. Appended overlay payloads and Windows driver-store filename masquerading combine to achieve zero detections across 76 antivirus engines. The certificate, issued in July 2024 and held unused for nearly two years, remains valid through June 2027.

Jun 21, 2026, 04:00 (UTC+9)Last seenJun 21, 2026Severity60ByCTX TeamActorKimsukyVelvet ChollimaIOC33MITRE44

A Nullsoft NSIS self-extracting installer bearing the filename npcap-1.88-oem-usnavy-testcopy-poexcu.exe — signed with a fully valid Nmap Software LLC code-signing certificate and scoring zero detections across 76 antivirus engines — represents one of the more deliberate evasion constructions CTX Team has documented in recent months.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence