APTMembers
APT

Expired and Revoked Certs Anchor Active Malware Delivery Chain

A delivery chain distributing PremierOpinion adware components and a widely circulated bundler is abusing two broken code-signing certificates — one expired, one explicitly revoked — from DigiCert and Certum EV issuers simultaneously. All three malicious PE samples share sandbox-evasion logic that produces near-zero dynamic verdicts despite static detection rates of 44–48 out of 76 engines. CTX Team has tracked the cluster, tagged to the surtr malware family, since August 2025.

Jun 6, 2026, 19:24 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC14MITRE7

Three Windows executables are circulating through software download channels carrying code-signing certificates that, by any standard enforcement logic, should stop them cold. One bears a DigiCert leaf certificate for an entity called VOICEFIVE, INC that expired on 3 April 2026. The other carries a Certum Extended Validation certificate for "AN Soft" that has been explicitly revoked.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence