A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows.
The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

See real exploitation activity before you spend the cycle.
28 events from the most recent confirmed update back to the earliest known activity.
Sekoia's July 2026 report detailed FakeBat distribution clusters, signed MSI and MSIX delivery, and command-and-control evolution from August 2023 through June 2024 across more than 130 domains.
The June 2026 post said Cert Graveyard had documented 2,400 unique certificates and described defender use cases, API access, downloadable feeds, and heavy usage statistics including tens of thousands of daily lookups.
The April 2026 post described CertGraveyard's purpose, reporting workflows, integrations, and partnerships, and stated the project had already helped report more than 2,000 abused certificates across many malware families.
SecurityAura published Microsoft Defender for Endpoint hunting and detection queries that compare endpoint certificate telemetry against the Cert Graveyard/CertReport dataset to identify suspicious signed EXE, DLL, MSI, and MSIX files. The guidance distinguishes exact certificate-serial matches from signer-only matches and recommends serial matches for high-confidence detections.
The Cert Graveyard author said the service experienced a DDoS attack in May 2025 that generated 85.51 million requests, with 82.9 million mitigated but 2.45 million still causing about 400 GB of transfer in minutes.
Squiblydoo said CertGraveyard was officially launched in January 2025 as a public project to document abused code-signing certificates used to sign malware and support revocation reporting.
The 'Quick abuse reports with certReport' post introduced certReport as a tool to automate creation of certificate abuse and revocation reports for signed malware using VirusTotal or MalwareBazaar data.
As of June 2024, Sekoia identified more than 250 websites containing FakeBat fake-browser-update code via PublicWWW and more than 120 allegedly compromised sites via FOFA.
Sekoia documented an infection chain on May 30, 2024 in which the typosquatted AnyDesk site amydlesk[.]com redirected users to download a malicious AnyDesk-x86.msix installer from monkeybeta[.]com.
On May 15, 2024, Sekoia uncovered a FakeBat campaign targeting the web3 community through a fake chat application branded as getmess[.]io and promoted via compromised social accounts.
In 'Impostor Certificates,' the author said 100 certificates were known to have been abused to sign SolarMarker malware and described a three-year pattern of repeated certificate fraud and replacement.
Sekoia reported that from late March to June 2024, FakeBat used /profile/, /profile1/, and later /buy/ endpoints on infrastructure hosted by Host Sailor Ltd.
According to Squiblydoo, the SolarMarker actor paused development and new infections from January 2024 until March 2024.
Sekoia said that since January 2024, FakeBat malvertising campaigns have used Google Ads and typosquatted landing pages impersonating legitimate software download sites.
Squiblydoo said that between September 2023 and January 2024, the SolarMarker actor signed and deployed malware multiple times each week instead of its usual weekly cadence.
Sekoia reported that in September 2023, FakeBat operators started advertising MSIX builds and valid code-signing certificates to help customers bypass Microsoft SmartScreen.
In 'Certified Bad,' the researcher documented and reported 50 Authenticode certificates for revocation after studying two years of SolarMarker certificate abuse and identifying collisions across 14 malware families.
Squiblydoo said the certificate tied to JuiceLedger, IcedID, and SolarMarker abuse remained active after reporting and was ultimately revoked on January 25, 2023.
Sekoia reported that the threat actor Eugenfest, also known as Payk_34, had been selling FakeBat as a Loader-as-a-Service offering on the Exploit forum since at least December 2022.
A certificate later discussed in Squiblydoo's collision analysis was reported by SentinelLabs as being abused by JuiceLedger on September 1, 2022, but it remained valid afterward.
Symantec said the Billbug campaign had been ongoing since at least March 2022, targeting a digital certificate authority as well as government and defense agencies in multiple Asian countries.
FortiGuard Labs received an email on February 12 requesting that Packity Networks software be whitelisted, then investigated the linked installer and identified a new threat cluster it named Netbounce.
The CertGraveyard author said they began concentrating on code-signing abuse in 2021 while trying to improve detections for SolarMarker, after observing the malware was signed with a code-signing certificate.
Malware Hunter Team discovered new Dark Caracal-associated Bandook samples in November 2019, and the samples were signed with legitimate Certum-issued Windows code-signing certificates.
A compromised remote support software update server began selectively delivering a malicious update containing 9002 RAT to targeted South Korean organizations. Update logs placed the start of the malicious process at around 13:35 on July 18, 2018.
Researchers inferred that the specific 9002 RAT activity associated with Operation Red Signature lasted roughly from July 18 to July 31, 2018, during which additional tools such as PlugX, Mimikatz, and an IIS exploit were delivered.
Trend Micro reported that researchers found a ShiftDoor malware sample signed with the stolen certificate on April 8, 2018, indicating the certificate may have been compromised as early as that month.
A GitHub project named certgraveyard_yara was published to automatically generate YARA detection rules from the CertGraveyard compromised certificate database. The tool downloads CertGraveyard CSV data, generates and validates per-certificate rules, and packages combined rulesets for release automation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 498 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
18 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceblog.sekoia.io
Open sourcegithub.com
Open sourcesquiblydoo.blog
Open sourceblog.trendmicro.com
Open sourceattack.mitre.org
Open sourceunpac.me
Open sourcecertgraveyard.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.