
TA505 Campaign Climbs Certificate Trust Ladder to Zero-Detection EV Binary
A piracy-lure campaign attributed to TA505 has assembled three distinct code-signing certificate chains — expired Sectigo, valid DigiCert, and a valid Extended Validation certificate issued to DeepL SE — each mapped to a progressively lower antivirus detection rate. The strategy culminates in a 64-bit binary that clears all 76 VirusTotal engines without a single flag, raising unresolved questions about how the threat actor obtained or abused a legitimate EV certificate from a named German software company.
A single campaign distributing trojanized KMS activators and download-manager reset tools has assembled one of the more deliberately layered code-signing abuse chains CTX Team has documented in recent months: an expired Sectigo leaf certificate that still evades roughly 38 antivirus engines, a currently valid DigiCert chain carrying a MediaGet PUA, and — at the top of the trust ladder — a valid Extended Validation certificate issued to DeepL SE under GlobalSign's GCC R45 hierarchy, producing a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read