
Revoked 2005 Certificate Still Delivering LSA Credential Stealer in 2026
A multi-component bundle combining NewDotNet and webHancer adware tooling — including an explicit LSA credential stealer — has been observed targeting telecoms in the UK and Mexico. Binaries signed with a certificate revoked two decades ago continued circulating as recently as March 2026, exploiting detection pipelines that deprioritise adware-classified threats.
A Windows executable bearing a webHancer Corporation code-signing certificate — issued by ThawteCode Signing CA, valid only from August 2004 to September 2005, explicitly distrusted, time-invalid, and with revocation status listed as offline — was submitted to threat intelligence platforms as recently as March 6, 2026. That single observation frames everything that follows: a multi-component bundle combining two distinct mid-2000s adware product lines, a versioned auto-update delivery mechanism…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read