FILEMembers
FILE

Kimsuky Hides Guloader Behind Fake 'Brittlewort' Code-Signing Identity

A Kimsuky-attributed spear-phishing campaign is delivering Guloader via a Polish-language purchase-order lure wrapped in an NSIS dropper signed with a fabricated self-signed certificate under the invented identity 'Brittlewort.' The campaign stacks four distinct evasion layers — invalid cert masquerade, PE timestamp forgery, sandbox fingerprinting, and a zero-detection second-stage payload buried in a browser-cache directory — to harden delivery against automated analysis pipelines.

Jun 2, 2026, 02:27 (UTC+9)Last seenJun 2, 2026Severity37ByCTX TeamActorKimsukyVelvet ChollimaIOC9MITRE18RegionsAUDEPL

A 326-kilobyte Windows executable named Zamówienie_Nr.2605011793800182.exe — Polish for "Order No." with a plausible invoice string appended — arrived in analysis pipelines on 18 May 2026 carrying a code-signing certificate issued by an entity called "Brittlewort." The name appears nowhere in any public certificate authority registry. It is self-issued, self-signed, and anchored to no trusted root.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence