• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Executable Signed with Discord Inc. or Lenovo Code-Signing Certificate

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•0

    This rule monitors Portable Executable (PE) files to identify those signed with certificates associated with Discord Inc. or Lenovo. Adversaries frequently abuse stolen or fraudulently obtained code-signing certificates from legitimate, reputable companies to bypass security controls like Windows SmartScreen, gain persistence, or increase the likelihood of successful malware execution.

    YARA

    Tags

    T1553.002 - Code SigningT1588.003 - Code Signing CertificatesFile Executable DetectedCertificate EventWindowsWindows Codeintegrity

    Found in

    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?