Malware Analysis - 3CX SmoothOperator Authenticode Abuse

Опубликовано: 27 Июнь 2026
на канале: MalwareAnalysisForHedgehogs
1,158
41

SmoothOperator abuses Microsoft Authenticode signatures to seem valid. Here is an explanation how it works and how to detect it in files.

Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter:   / struppigel  

AnalysePESig: https://blog.didierstevens.com/progra...

SigFlip: https://github.com/med0x2e/SigFlip

Sysinternals: https://learn.microsoft.com/en-us/sys...

Using unauthenticated data inside authenticode signed binaries: https://web.archive.org/web/201504261...

Samples:
3CXDesktopApp.msi: https://tria.ge/230330-3nzfjshc2s
ffmpeg: https://bazaar.abuse.ch/sample/7986bb...
d3dcompiler_47.dll: https://bazaar.abuse.ch/sample/11be18...

00:00 Intro
00:37 Signature verification
02:09 SigFlip and SigLoader
03:05 Ways to hide data in authenticode structures
06:00 Detecting hidden authenticode data
08:11 Why this still works
09:05 Outro

#malware #malwareanalysis #reverseengineering #3cx #authenticode