Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Point researchers linked SSL.com code-signing certificates to malware used in activity they track as Nimbus Manticore, which overlaps with the Iran-linked actor UNC1549. Check Point dates the start of the observed certificate use to May 2025. The certificates made the malware appear signed by identifiable organizations, and Check Point said signing helped reduce detections—but it was one part of a broader evasion strategy, not a guaranteed way past security software.

What researchers reported

In a technical analysis dated September 22, 2025, Check Point Research described a campaign targeting organizations in Western Europe, including in Denmark, Sweden, and Portugal. The sectors included defense manufacturing, telecommunications, and aviation; Check Point also noted that earlier operations had targeted the Middle East. The researchers track the campaign as Nimbus Manticore and report overlap with UNC1549 and Smoke Sandstorm. These names reflect researchers’ tracking and attribution; the reporting does not establish that every alias refers to an exactly equivalent organization.

Rob Wright’s September 26, 2025, Dark Reading report said Check Point and PRODAFT associated SSL.com certificates with malware used in UNC1549 activity. Dark Reading updated its report on December 1, 2025, with a statement from Oskar Lund, owner of Sevenfeet Software AB, that his company had been impersonated and that the spoofed domain was taken down at his request.

How the campaign delivered the malware

Check Point described a recruiting-themed spear-phishing operation. Targets were directed to fake career portals and, after logging in, offered archives presented as software for a hiring process. The staged infection used legitimate Windows executables to load malicious DLLs and establish persistence. In the detailed sample, a Windows Defender component was abused in the DLL-loading chain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the malware did

  • MiniJunk was identified as a backdoor.
  • MiniBrowse was described as a lightweight stealer; variants targeted credentials stored in Chrome or Edge.

Check Point also documented obfuscation, junk-code insertion, inflated file sizes, and multi-stage DLL sideloading. Those techniques, alongside code signing, complicated detection and analysis.

Why a valid signature did not make the files safe

Code signing connects a file to a signer identity. That can make a file look more trustworthy to a person or security system, but it does not certify that the file is harmless. Check Point said the use of signing contributed to a decrease in detections. Its report, as quoted in Dark Reading, said that “many samples” remained undetectable by multiple malware engines; the reporting provides no incident-wide detection-rate percentage and does not show that every security product was bypassed.

Signing was only one factor. The campaign also used phishing, staged delivery, DLL sideloading, and other evasion techniques. A valid signature therefore belongs in the investigation—not as a clean bill of health, nor as proof by itself that a file is malicious.

What is known about the certificates—and what is not

According to PRODAFT, as summarized by Dark Reading, malicious UNC1549 binaries were signed with an SSL.com certificate issued to Dutch company Insight Digital B.V. Related certificates were associated with Swedish companies RGC Digital AB and Sevenfeet Software AB. Lund’s statement establishes that Sevenfeet Software AB said it had been impersonated. The reporting does not establish whether Insight Digital B.V. or RGC Digital AB were fabricated organizations or real companies being impersonated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The exact route by which the certificates were obtained remains unresolved. Dark Reading reported that it was unclear what information the actors submitted to SSL.com or whether it was convincing; the reporting does not provide a complete issuance audit or forensic account of the applications. It also does not establish SSL.com’s full remediation or the present validity of every certificate.

Dark Reading reported that three of the four certificates Check Point had observed in the latest UNC1549 activity were still valid at the time of its 2025 reporting. That is a dated observation, not a statement of their status now. The article also summarized CA/Browser Forum baseline requirements as calling for revocation within 24 hours after a certificate authority has evidence of misuse, with revocation completed within five days. Those requirements do not establish whether or when SSL.com complied in this case.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How defenders can investigate suspiciously signed files

Dark Reading points to two complementary approaches: match known indicators such as file hashes, and review signer and file metadata for unexpected combinations. A hash can help identify a known sample; metadata review can raise questions about a new or modified file. Neither approach alone proves that a file is safe or malicious.

Check known indicators

Use the indicators of compromise published by Check Point, including file hashes, in detection rules. A matching hash is useful evidence for identifying a known sample, but a hash-based rule will not by itself identify a different file that has not been observed before.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review signer identity and file context

  • Check whether the signer makes sense for the software the file claims to be. An unexpected mismatch is a reason to investigate, not conclusive proof of malware.
  • Scrutinize unusually close file-creation and signature times, particularly for an installer claiming to belong to a well-established application. Red Canary researchers quoted by Dark Reading cautioned that recent creation time can be a leading indicator, while noting that not every new binary is malicious.
  • Consider the file alongside its delivery path, behavior, and other indicators. In this campaign, the recruiting lure, archive, and DLL sideloading are relevant context for evaluating a signed file.

Combining these checks helps distinguish known samples from suspicious new files without treating a certificate—or any single metadata clue—as a verdict.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.