
Expired Certificate Still Trusted in Four-Named Bundler
A single PUA bundler, submitted 11,721 times under four different installer disguises, keeps running as a trusted signed binary even though its code-signing leaf certificate expired over a year ago. The intermediate and root chain behind it still validate, exposing a gap between leaf-certificate expiry and chain-based trust checks.
A single Win32 binary has been submitted to detection platforms 11,721 times from 3,694 distinct sources while wearing four different disguises — packaged and distributed as a Resource Hacker installer, an XMEye VMS setup file, a KeyTweak utility, and a glogg build. The file, catalogued under the threat label `adware.bundler/cppinstaller with popular names bundler, cppinstaller, and installcore, is the kind of high-volume, low-sophistication artifact that rarely gets a deep look — until you…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read