FILEMembers
FILE

Fake 'Sanwhole' Cert Anchors Layered Crypto-Wallet Heist via Trojanised IDE

A trojanised installer impersonating developer tool 'Netpas DevStudio' deploys a Cryptbot-family infostealer signed with a wholly fabricated 'Sanwhole' code-signing certificate whose chain terminates in an untrusted root. The bundle combines hardware-fingerprinting sandbox evasion, a DLL spoofing ntdll.dll, and a DGA-pattern C2 domain to harvest Exodus and Coinomi cryptocurrency wallet credentials that score zero detections across 77 antivirus engines.

Jun 9, 2026, 08:22 (UTC+9)Last seenJun 9, 2026Severity72ByCTX TeamActorEmotet GroupTA542IOC33MITRE39RegionsCI

A trojanised installer impersonating the developer tool "Netpas DevStudio" has been circulating with a self-fabricated code-signing certificate — issued by and to a fictitious entity called "Sanwhole" — whose chain terminates in an untrusted root that no legitimate certificate authority ever vouched for. Three files in the bundle carry the same fraudulent signature, the same certificate serial (26 F4 9B CA 07 79 1C 96 48 EA 3D 5A EA 7F 69 37), and the same thumbprint…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence