FILEMembers
FILE

Revoked 2005 Certificate Still Delivering LSA Credential Stealer in 2026

A multi-component bundle combining NewDotNet and webHancer adware tooling — including an explicit LSA credential stealer — has been observed targeting telecoms in the UK and Mexico. Binaries signed with a certificate revoked two decades ago continued circulating as recently as March 2026, exploiting detection pipelines that deprioritise adware-classified threats.

Jun 22, 2026, 18:33 (UTC+9)Last seenJun 22, 2026Severity72ByCTX TeamIOC24MITRE43RegionsGBMX

A Windows executable bearing a webHancer Corporation code-signing certificate — issued by ThawteCode Signing CA, valid only from August 2004 to September 2005, explicitly distrusted, time-invalid, and with revocation status listed as offline — was submitted to threat intelligence platforms as recently as March 6, 2026. That single observation frames everything that follows: a multi-component bundle combining two distinct mid-2000s adware product lines, a versioned auto-update delivery mechanism…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence