C&CMembers
C&C

TA505 Hides Malware Behind 13-Year-Old Revoked Valve Certificate

A TA505-attributed campaign pairs gaming-mod lures with a stolen, revoked Valve code-signing certificate, a BYOVD WinDivert kernel driver, and a compromised Turkish university domain to stage LummaStealer, SalatStealer, and an Amadey loader. The three-layer evasion stack — targeting signature verification, kernel-level security tooling, and URL-reputation filtering simultaneously — reflects an unusually mature operational investment for a financially motivated actor.

Jun 7, 2026, 03:39 (UTC+9)Last seenJun 7, 2026Severity100ByCTX TeamActorTA505Hive0065IOC30MITRE27

A SilverFox dropper circulating since early June 2026 carries a Valve Corporation code-signing certificate that expired in November 2012 and has been explicitly revoked — yet its PE timestamp reads 2025-08-18, a 13-year anachronism that is the clearest single indicator of deliberate stolen-cert abuse in this campaign. That certificate is only the first layer of a defense-evasion stack that also includes a Bring Your Own Vulnerable Driver (BYOVD) technique using a legitimately signed WinDivert…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence