FILEMembers
FILE

Fake Microsoft Installer Trips Three Rival Malware Signatures at Once

A loader masquerading as Windows' Wextract component carries an expired, unverifiable Microsoft signer chain and simultaneously trips YARA rules built for Andariel's vsingle packer, Cobalt Strike's beacon loader, and Formbook's anti-hook bypass. Analysts say that three-way rule collision inside one binary is the notable finding — more so than the thin two-domain infrastructure cluster it connects to via a single DNS-lookup IDS alert.

Aug 29, 2026, 14:41 (UTC+9)Last seenSep 10, 2026Severity77ByCTX TeamActorSilent ChollimaAndarielIOC13MITRE16RegionsCNUS

A loader dressed up as Wextract, the innocuous Windows component that unpacks self-extracting installer packages, carries a Microsoft Corporation signer chain that fails validation outright — and once analysts looked past the broken signature, the binary turned out to simultaneously trip YARA rules built for three unrelated malware lineages: an Andariel-linked packer signature, a Cobalt Strike beacon-loader rule, and a Formbook anti-hook bypass routine.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence