APTMembers
APT

Expired Certificate, Still Trusted: A Bundler Wearing Four Disguises

A single Win32 installer spoofing Resource Hacker, XMEye, KeyTweak, and glogg keeps registering as 'Signed' even though its own leaf certificate has expired, because the Sectigo chain above it remains valid. The finding says more about weaknesses in code-signing trust logic than about the two APT actors loosely tagged to the same feed entry.

Jul 11, 2026, 05:33 (UTC+9)Last seenJul 11, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC21MITRE10

A single Win32 binary circulating under the guise of at least four unrelated software titles — Resource Hacker, the XMEye video-surveillance client, the KeyTweak keyboard remapper, and the log viewer glogg — carries a code-signing chain that keeps presenting as "Signed" to Windows even though its own leaf certificate has expired.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence