
Recycled Sectigo Certificate Links Loader and Banking-Trojan Payload
A revoked MASTER LIM LTD code-signing certificate chained through Sectigo/Comodo appears on both an NSIS installer and the banking-trojan DLL it drops, tying the two stages to a single signing identity. The finding anchors a 2018-vintage, three-stage delivery chain that begins with a malicious Excel macrosheet.
The same revoked leaf certificate — serial 00 8E 3E 9A 2F E7 3C 91 98 5B 4F 90 D5 95 77 CD 6C, issued under the name MASTER LIM LTD and chained through COMODO RSA Code Signing CA up to Sectigo (formerly Comodo CA) — is stamped on two files that sit at opposite ends of a delivery chain: an NSIS self-extracting installer and the banking-trojan DLL it ultimately drops.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read