
TA505 Hides Malware Behind 13-Year-Old Revoked Valve Certificate
A TA505-attributed campaign pairs gaming-mod lures with a stolen, revoked Valve code-signing certificate, a BYOVD WinDivert kernel driver, and a compromised Turkish university domain to stage LummaStealer, SalatStealer, and an Amadey loader. The three-layer evasion stack — targeting signature verification, kernel-level security tooling, and URL-reputation filtering simultaneously — reflects an unusually mature operational investment for a financially motivated actor.
A SilverFox dropper circulating since early June 2026 carries a Valve Corporation code-signing certificate that expired in November 2012 and has been explicitly revoked — yet its PE timestamp reads 2025-08-18, a 13-year anachronism that is the clearest single indicator of deliberate stolen-cert abuse in this campaign. That certificate is only the first layer of a defense-evasion stack that also includes a Bring Your Own Vulnerable Driver (BYOVD) technique using a legitimately signed WinDivert…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read