
Expired-Cert Installer Evades Sandboxes, Feeds 15-Domain Crypto Fraud Net
A 4.3 MB Windows installer impersonating popular freeware uses a five-technique anti-sandbox suite and an expired Sectigo code-signing certificate to slip past automated defences. Once clear, it routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains toward credential harvesting and crypto fraud.
A 4.3-megabyte Windows installer, dressed in the branding of legitimate freeware and carrying a Sectigo-issued code-signing certificate that had already expired, is the entry point for a financially motivated campaign that routes victims through a Cloudflare-proxied network of at least fifteen crypto-faucet, gambling, and phishing domains.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read