Technical Analysis of Code-Signed “Blister” Malware Campaign (Part 1)
ID: 3242ea7b-0320-5aae-9fd3-decf3bbf1f9a
STIX ID: report--3242ea7b-0320-5aae-9fd3-decf3bbf1f9a
Feed Name: CloudSEK Blog
Threat Score
This report analyzes the "Blister" malware campaign that abuses Sectigo code-signing certificates to sign loader binaries, drops a second-stage DLL (examples: C:\Users\<user>\AppData\Local\Temp\goalgames\holorui.dll), and executes its LaunchColorCpl export via rundll32.exe to load a RAT/CobaltStrike beacon; it includes API-level behavioral details, certificate evidence (revocation noted), and IoCs (hashes, domains, IPv4 addresses, and signed loader hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
