#signed


ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

Aug 31, 2026 // 20:53

The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under […]

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

Aug 14, 2026 // 16:16

The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode […]

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

May 12, 2026 // 14:36

Hundreds of packages across npm, PyPI, and Composer have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. The attacker hijacked […]

Signed software abused to deploy antivirus-killing scripts

Apr 15, 2026 // 21:17

A digitally signed adware tool has deployed payloads running with SYSTEM privileges that disabled antivirus protections on thousands of endpoints, some in the educational, utilities, […]

BYOVD Used to Disable Security: 54 EDR Killers Exploit 35 Vulnerable, Signed Drivers.

Mar 20, 2026 // 11:14

A fresh examination of programs designed to disable endpoint detection and response (EDR) solutions has found that 54 of them exploit a “bring your own […]