typetechniqueconfidencemediumcreated2026-09-03updated2026-09-03evasiondefense-evasionanti-sandboxanti-analysissigning

signed-carrier-combo

Malware evasion technique that combines a valid Authenticode-signed carrier PE with an encrypted companion payload distributed inside a silent self-extracting archive (typically 7-Zip SFX). The signed carrier binary is either a stolen or misappropriated legitimate executable, or a malware binary that has acquired a valid code-signing certificate. The companion payload is encrypted and masquerades with a benign filename extension (.xml, .map, .yaml, .sym).

Why It Works

  1. Signature trust: EDR, SmartScreen, and application-whitelisting products typically trust processes launched from signed binaries, especially when the certificate chain traces to a trusted root CA (Microsoft, DigiCert, Sectigo).
  2. Split payload: Sandboxes that detonate only the outer archive or only the extracted carrier miss the encrypted companion, which contains the actual malicious logic. The carrier's import table is entirely benign (standard Windows + Office APIs).
  3. Silent extraction: 7-Zip SFX with Progress=no and GUIFlags=8 extracts to %TEMP% with no user-visible window, then auto-launches the carrier. The victim sees only a brief spinner.

Variants Observed

  • GhostPulse — InfoPath morph (4a78e2ad) — 7-Zip SFX archive containing a renamed Microsoft InfoPath 2013 x64 executable (GeneratorB64.exe) with valid Microsoft Authenticode chain, two Office Common Dialog Framework DLLs (CDLMSO.DLL, MSOCF.DLL), and a 7.6 MB encrypted sidecar kernel-layer.xml (entropy 7.90). Carrier imports standard Windows + Office APIs; no malicious imports visible. ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]

  • GhostPulse — Steam Error Reporter morph (833bffd0) — 7-Zip SFX archive containing Valve's signed SteamErrorReporter.exe (Authenticode by DigiCert), Qt5 runtime DLLs, and encrypted companion texture_mon.yaml. Carrier is an actual Valve binary repurposed as a dropper. ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]

Detection

Indicator Detection Target
SFX archive >8 MB with 7ZSfxMod or 7z SFX strings Static file carving
RunProgram in 7-Zip SFX config pointing to a renamed binary Config parser / YARA
Signed binary in %TEMP% reading a high-entropy companion file EDR behavioural rule
Entropy >7.8 on .xml/.yaml/.map files in temp dirs File-system monitoring
Import table mismatch: signed Office binary loading custom unsigned DLLs Memory / import-table analysis
Certificate subject CN mismatch with executable filename (e.g., Microsoft Corporation vs GeneratorB64.exe) Certificate telemetry correlation

Related