C&CMembers
C&C

TA505 Campaign Climbs Certificate Trust Ladder to Zero-Detection EV Binary

A piracy-lure campaign attributed to TA505 has assembled three distinct code-signing certificate chains — expired Sectigo, valid DigiCert, and a valid Extended Validation certificate issued to DeepL SE — each mapped to a progressively lower antivirus detection rate. The strategy culminates in a 64-bit binary that clears all 76 VirusTotal engines without a single flag, raising unresolved questions about how the threat actor obtained or abused a legitimate EV certificate from a named German software company.

Jun 3, 2026, 09:00 (UTC+9)Last seenJun 3, 2026Severity100ByCTX TeamActorTA505Hive0065IOC15MITRE29

A single campaign distributing trojanized KMS activators and download-manager reset tools has assembled one of the more deliberately layered code-signing abuse chains CTX Team has documented in recent months: an expired Sectigo leaf certificate that still evades roughly 38 antivirus engines, a currently valid DigiCert chain carrying a MediaGet PUA, and — at the top of the trust ladder — a valid Extended Validation certificate issued to DeepL SE under GlobalSign's GCC R45 hierarchy, producing a…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence