Code-signing certificate abuse in the Black Basta chat leaks (and how to fight back)
ID: 5bca127d-8897-51d9-b99e-5682552b5960
STIX ID: report--5bca127d-8897-51d9-b99e-5682552b5960
Feed Name: Expel Blog
Threat Score
Black Basta chat leaks reveal the gang systematically purchases and uses impersonated EV code-signing certificates to sign a range of malware and delivery artifacts (documenting ~28 identified certificates and sample hashes), describing pricing, operational workflows, and advising defenders to investigate suspiciously signed files and report abused certificates to disrupt campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
