FILEMembers
FILE

One Softonic EV Signature, Two Unrelated Malware Installers

A single Sectigo EV code-signing certificate issued to Softonic underpins two structurally unrelated Windows installers masquerading as Hamachi, Termux, and other consumer apps. Same signer and timestamp, but different imphashes, different fuzzy hashes, and a nearly 2x size gap point to one signing pipeline wrapping multiple unrelated payloads.

Jul 5, 2026, 16:36 (UTC+9)Last seenJul 5, 2026Severity62ByCTX TeamActorDustSquadAPTC34IOC5MITRE16RegionsEC

A single Sectigo EV code-signing certificate — issued to SOFTONIC INTERNATIONAL SA and timestamped 04:20 PM on 06/24/2025 — sits behind two structurally unrelated Windows installers now circulating under the names of Hamachi, Termux, a casual game called "bee-movie-game," and a reminder utility called "minireminder." The binaries, catalogued as 68e4a2bfe728081eb1a84369f7dbad74c12c06a306cd5ad974ded8df3283a2ad and e8c438babbc09306f7a903f6e8f78b59ed395c81d541417c1b009b45bdc77040, share the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence