Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Aryeh Goretsky

@goretsky@infosec.exchange
  • Open on infosec.exchange

Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades.

Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee.

Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.

0 Followers
0 Following
4 Posts
Joined November 03, 2022
Blog (work):
https://www.welivesecurity.com/authors/goretsky
Blog (personal):
https://goretsky.wordpress.com/
🦋:
https://bsky.app/profile/goretsky.bsky.social
Reddit:
https://www.reddit.com/u/goretsky

Posts

Open post
goretsky
Aryeh Goretsky @goretsky@infosec.exchange · Jul 31, 2026
Aryeh Goretsky
@goretsky@infosec.exchange

Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.

infosec.exchange
Just saw a report of an information stealer (aka ClickFix) malware using the finger command to retrieve and execute its payload. I thought finger was deprecated on Windows, but apparently the binary is still there. Definitely getting Morris Worm vibes. https://old.reddit.com/r/antivirus/comments/1v9ota6/help_asap_what_do_i_do/
0
1
0
0
Open post
goretsky
Aryeh Goretsky @goretsky@infosec.exchange · Jul 22, 2026
Aryeh Goretsky
@goretsky@infosec.exchange

Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.

infosec.exchange
Just read a message saying that the Scouting America (formerly Boy Scouts of America) website is pushing information-stealing malware: https://old.reddit.com/r/antivirus/comments/1v1xknb/what_tf_is_this/
0
0
0
0
Open post
goretsky
Aryeh Goretsky @goretsky@infosec.exchange · Jul 01, 2026
Aryeh Goretsky
@goretsky@infosec.exchange

Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.

infosec.exchange
Replying to on securitycafe.ca
@chetwisniewski@securitycafe.ca I know it is a little outside of normal infosec writing, but this is kind of a trending topic due to DRAM and NAND scarcity. Might make for a good blog post, especially if you tie in the 🇨🇦 perspective.
0
0
0
0
Open post
goretsky
Aryeh Goretsky @goretsky@infosec.exchange · May 03, 2026
Aryeh Goretsky
@goretsky@infosec.exchange

Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.

infosec.exchange

[UPDATE 20260503-2020 UTC: Clarified type of certificate involved since it appears there may be two unrelated certificate revocations that were conflated as one event. ^AG]

This is an evolving situation, but it appears that a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate issued by #DigiCert was stolen by a threat actor for misuse.

#Microsoft is now detecting the stolen code-signing certificate as "Trojan:Win32/Cerdigent.A!dha" via Microsoft Windows Defender, with a not-yet-very-detailed entry about it at:
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Cerdigent.A!dha&ThreatID=2147968144

Computer security researcher @cyb3rops@infosec.exchange has a discussion about it on Twitter at:
https://x.com/cyb3rops/status/2050916842730869197

as well as the following update:
https://x.com/cyb3rops/status/2050924042173943820

This discussion may or may not be related to the 𝗿𝗼𝗼𝘁 certificate issue. It discusses stolen code-signing certificates:
T̶h̶e̶r̶e̶'̶s̶ ̶a̶ ̶s̶o̶m̶e̶w̶h̶a̶t̶ ̶t̶e̶c̶h̶n̶i̶c̶a̶l̶ ̶d̶i̶s̶c̶u̶s̶s̶i̶o̶n̶ ̶o̶f̶ ̶t̶h̶e̶ ̶t̶h̶e̶f̶t̶ ̶i̶n̶ ̶M̶o̶z̶i̶l̶l̶a̶'̶s̶ ̶b̶u̶g̶ ̶d̶a̶t̶a̶b̶a̶s̶e̶ ̶a̶s̶ ̶w̶e̶l̶l̶:̶
https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

There's also an ongoing discussion on Reddit about it as well at:
https://old.reddit.com/r/antivirus/comments/1t2l6tk/windows_defender_picked_up_a_trojan_what_do_i_do/

At this point, there's not really a lot for most Windows users to do here. This is, or at least was, a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate, so its presence on a system is not unexpected. And just because it was found on a system does not mean the system has malware on it or was targeted by a threat actor.

I recommend monitoring the situation and wait for additional clarification from Microsoft.

2
0
4
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:01:39 UTC