Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Aryeh Goretsky

@goretsky@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades.

Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee.

Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.

0 Followers
0 Following
6 Posts
Joined November 03, 2022
Blog (work):
https://www.welivesecurity.com/authors/goretsky
Blog (personal):
https://goretsky.wordpress.com/
🦋:
https://bsky.app/profile/goretsky.bsky.social
Reddit:
https://www.reddit.com/u/goretsky
Open post
Aryeh Goretsky @goretsky@infosec.exchange
· 2w ago
Electronics manufacturer #Elecrow has released an advisory that their #ThinkNode M9 LoRA mesh node's internal Micro SD cards shipped with Windows malware on them: https://www.elecrow.com/Thinknode-M9-Security-Advisory-SD-Card-Malware-Risk.html These are hobbyist devices based on the ESP32 chip, and run specialized firmware like Meshtastic and MeshCore for peer-to-peer communications, and the device's firmware itself is unaffected. Based on the description and screenshots, it appears to Win32/Virut, an old family of parasitic file infectors that also engage in wormlike behavior by spreading as USB worms via AUTORUN.INF, a mechanism that Microsoft disabled by default in 2009 with the release of Windows 7 (and backported those changes to Windows Vista and Windows XP). The Virut family is very old, and detection of the malware is quite high by modern security software. While the risk of accidentally running and spreading the malware is low, it is important to follow Elecrow's instructions for remediation if you have an affected device.
elecrow.com
1
1
11
0
Open post
Aryeh Goretsky @goretsky@infosec.exchange
· 5mo ago

[UPDATE 20260503-2020 UTC: Clarified type of certificate involved since it appears there may be two unrelated certificate revocations that were conflated as one event. ^AG]

This is an evolving situation, but it appears that a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate issued by #DigiCert was stolen by a threat actor for misuse.

#Microsoft is now detecting the stolen code-signing certificate as "Trojan:Win32/Cerdigent.A!dha" via Microsoft Windows Defender, with a not-yet-very-detailed entry about it at:
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Cerdigent.A!dha&ThreatID=2147968144

Computer security researcher @cyb3rops@infosec.exchange has a discussion about it on Twitter at:
https://x.com/cyb3rops/status/2050916842730869197

as well as the following update:
https://x.com/cyb3rops/status/2050924042173943820

This discussion may or may not be related to the 𝗿𝗼𝗼𝘁 certificate issue. It discusses stolen code-signing certificates:
T̶h̶e̶r̶e̶'̶s̶ ̶a̶ ̶s̶o̶m̶e̶w̶h̶a̶t̶ ̶t̶e̶c̶h̶n̶i̶c̶a̶l̶ ̶d̶i̶s̶c̶u̶s̶s̶i̶o̶n̶ ̶o̶f̶ ̶t̶h̶e̶ ̶t̶h̶e̶f̶t̶ ̶i̶n̶ ̶M̶o̶z̶i̶l̶l̶a̶'̶s̶ ̶b̶u̶g̶ ̶d̶a̶t̶a̶b̶a̶s̶e̶ ̶a̶s̶ ̶w̶e̶l̶l̶:̶
https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

There's also an ongoing discussion on Reddit about it as well at:
https://old.reddit.com/r/antivirus/comments/1t2l6tk/windows_defender_picked_up_a_trojan_what_do_i_do/

At this point, there's not really a lot for most Windows users to do here. This is, or at least was, a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate, so its presence on a system is not unexpected. And just because it was found on a system does not mean the system has malware on it or was targeted by a threat actor.

I recommend monitoring the situation and wait for additional clarification from Microsoft.

x.com
2
0
4
0
Open post
Aryeh Goretsky @goretsky@infosec.exchange
· 2mo ago
Just read a message saying that the Scouting America (formerly Boy Scouts of America) website is pushing information-stealing malware: https://old.reddit.com/r/antivirus/comments/1v1xknb/what_tf_is_this/
old.reddit.com
0
0
0
0
Open post
Aryeh Goretsky @goretsky@infosec.exchange
· 2mo ago
Just saw a report of an information stealer (aka ClickFix) malware using the finger command to retrieve and execute its payload. I thought finger was deprecated on Windows, but apparently the binary is still there. Definitely getting Morris Worm vibes. https://old.reddit.com/r/antivirus/comments/1v9ota6/help_asap_what_do_i_do/
old.reddit.com
0
1
0
0
Open post
Aryeh Goretsky @goretsky@infosec.exchange
· 2w ago
Replying to

Hello @Judeau@mas.to, It is hard to say what happened without an explanation from the company, but in the past shipping infected media and even computers was usually the result of a number of things:

  1. Old and/or obsolete computers were used during the manufacturing process, and these had no modern protections that newer OSes have, including running up-to-date antivirus software.

  2. Use of pirated operating systems or software during the manufacturing process to cut operating costs.

  3. Improper security controls on the manufacturing line. The computers used to make the devices might not have been dedicated to just manufacturing and have been used for other things (web browsing, email, downloading and running random software, and so on).

Any of these, or a combination of them could have led to the company shipping malware. However, I'll also note that unless they have an investigation and share it, this all remains hypothetical and we'll likely never know the source.

0
0
0
0
Open post
Aryeh Goretsky @goretsky@infosec.exchange
· 3mo ago
Replying to on securitycafe.ca
@chetwisniewski@securitycafe.ca I know it is a little outside of normal infosec writing, but this is kind of a trending topic due to DRAM and NAND scarcity. Might make for a good blog post, especially if you tie in the 🇨🇦 perspective.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:02:59 UTC