
Kimsuky Hides Guloader Behind Fake 'Brittlewort' Code-Signing Identity
A Kimsuky-attributed spear-phishing campaign is delivering Guloader via a Polish-language purchase-order lure wrapped in an NSIS dropper signed with a fabricated self-signed certificate under the invented identity 'Brittlewort.' The campaign stacks four distinct evasion layers — invalid cert masquerade, PE timestamp forgery, sandbox fingerprinting, and a zero-detection second-stage payload buried in a browser-cache directory — to harden delivery against automated analysis pipelines.
A 326-kilobyte Windows executable named Zamówienie_Nr.2605011793800182.exe — Polish for "Order No." with a plausible invoice string appended — arrived in analysis pipelines on 18 May 2026 carrying a code-signing certificate issued by an entity called "Brittlewort." The name appears nowhere in any public certificate authority registry. It is self-issued, self-signed, and anchored to no trusted root.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read