logo

How Threat Actors Weaponize EV Certificates by Lucie Cardiet

ID: 4bad3aa8-7d7f-5031-8b14-1e0a8b47e5d3

STIX ID: report--4bad3aa8-7d7f-5031-8b14-1e0a8b47e5d3

Feed Name: Vectra AI Blog

Threat Score
80/100

Date Published: 2025-04-01

Date Updated: 2026-05-01

...
...

Leaked Black Basta chat logs reveal the group obtains and abuses Extended Validation (EV) code-signing certificates—via purchase from underground markets or by remotely accessing stolen hardware tokens (YubiKey through VirtualHere)—to sign MSIs, VBS loaders, and malware (including ransomware, PikaBot, and Cobalt Strike), allowing payloads to bypass signature-based defenses; the report includes exact signtool and .pfx signing procedures, evidence of automation and certificate repositories, and recommends behavior-based detection and EDR integration as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.