logo

Technical Analysis of Code-Signed “Blister” Malware Campaign (Part 1)

ID: 3242ea7b-0320-5aae-9fd3-decf3bbf1f9a

STIX ID: report--3242ea7b-0320-5aae-9fd3-decf3bbf1f9a

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2022-01-07

Date Updated: 2026-04-27

...
...

This report analyzes the "Blister" malware campaign that abuses Sectigo code-signing certificates to sign loader binaries, drops a second-stage DLL (examples: C:\Users\<user>\AppData\Local\Temp\goalgames\holorui.dll), and executes its LaunchColorCpl export via rundll32.exe to load a RAT/CobaltStrike beacon; it includes API-level behavioral details, certificate evidence (revocation noted), and IoCs (hashes, domains, IPv4 addresses, and signed loader hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.