logo

Microsoft Trusted Signing service abused to code-sign malware

ID: 595e6e9c-743b-5636-b12c-6c2c61cff450

STIX ID: report--595e6e9c-743b-5636-b12c-6c2c61cff450

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-03-22

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Cybercriminals have been observed abusing Microsoft’s Trusted Signing service to obtain short-lived (three-day) code-signing certificates and sign malware samples, enabling them to evade security warnings and improve file reputation; multiple active campaigns (including crypto-theft and info-stealer activity) have been linked to these signed binaries, and Microsoft reports active monitoring, certificate revocation, and account suspension to mitigate the abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.