
Expired and Revoked Certs Anchor Active Malware Delivery Chain
A delivery chain distributing PremierOpinion adware components and a widely circulated bundler is abusing two broken code-signing certificates — one expired, one explicitly revoked — from DigiCert and Certum EV issuers simultaneously. All three malicious PE samples share sandbox-evasion logic that produces near-zero dynamic verdicts despite static detection rates of 44–48 out of 76 engines. CTX Team has tracked the cluster, tagged to the surtr malware family, since August 2025.
Three Windows executables are circulating through software download channels carrying code-signing certificates that, by any standard enforcement logic, should stop them cold. One bears a DigiCert leaf certificate for an entity called VOICEFIVE, INC that expired on 3 April 2026. The other carries a Certum Extended Validation certificate for "AN Soft" that has been explicitly revoked.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read