Researchers linked the operators behind OpenSUpdater to two code-signing abuse techniques designed to keep suspicious Windows executables looking trustworthy. In one campaign, the actor impersonated software company executives, registered lookalike domains, and passed certificate authority business validation to obtain legitimate code-signing certificates. ReversingLabs said those certificates were later used to sign OpenSUpdater samples, with evidence of certificate-authority hopping, repeated impersonation across multiple companies, and in some cases successful acquisition of extended validation certificates that can help bypass Microsoft SmartScreen warnings.
Google’s Threat Analysis Group later reported that OpenSUpdater samples also began carrying deliberately malformed code signatures that appeared valid to Windows while breaking parsing in some security tools. The manipulation altered the leaf X.509 certificate by replacing the expected NULL tag in the SignatureAlgorithm parameters field with an End of Content marker, causing stricter parsers such as OpenSSL-based implementations to reject the signature as invalid even as Windows and more permissive parsers could still accept it. Google said the financially motivated actor appeared focused on broad distribution, particularly targeting users seeking game cracks and other gray-market software, and described the technique as a novel way to preserve an apparently valid PE-file signature while evading detection.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Since mid-August 2021, OpenSUpdater samples were observed carrying deliberately malformed code signatures designed to evade security products while still appearing valid to Windows. The manipulation replaced the NULL tag in the leaf certificate's SignatureAlgorithm parameters with an End of Content marker.
The last malicious file signed with the certificate in this observed campaign was spotted on May 16, 2019. Across the activity window, the certificate was used to sign 22 executables, with malicious samples belonging to the OpenSUpdater family.
The first malicious file signed with the fraudulently obtained certificate was observed in the wild. ReversingLabs identified it as OpenSUpdater, an adware family used to install unwanted software.
The actor used the obtained code-signing certificate to sign benign test files, including Notepad.exe and an NSIS installer, and uploaded them to a public antivirus scanning service. These files were used to validate the certificate and timestamping workflow before malicious use.
A financially motivated actor registered a lookalike .co.uk domain to impersonate a UK software company and support a fraudulent code-signing certificate application. The domain was used to mislead the certificate authority while redirecting web traffic to the legitimate .com site.
Google's Threat Analysis Group reported the malformed-but-apparently-valid signature issue affecting OpenSUpdater samples to Microsoft. TAG described it as the first time it had observed this technique used to preserve a valid PE-file signature while evading detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.