Some findings:
- The C2: 54.39.43[.]117 (WIN-6HTEEE5UVML)
- The TA's Firebase project: my-first-metamask-39906
- Firestore collection: wallet_Information
- Previous repo they had but was removed: hxxps://github[.]com/centrelocuslabs/Jackpot-v1/
- Victims across Italy, Belgium, and the US - all within 24 hours.
Lessons learned from here:
- Do not ever connect your crypto wallets on sketchy sites
- Take-homes and "collab repos" from any recruiter, real or fake, run in a VM. No wallets, no creds, no .env, no route back to your home network.
- The profile picture looks AI generated - do your basic OSINT and if that fails - use AI image detectors e.g. wasitai[.]com
Anyone else seeing Microsoft #Defender flagging #DigiCert root certificate registry keys as malware?
We’ve seen reports that Defender signature update from April 30 added a detection called:
Trojan:Win32/Cerdigent.A!dha
In some environments, Defender apparently detected DigiCert Root CA certificate registry entries and removed them from the trust store.
The affected cert hashes mentioned so far:
0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
DDFB16CD4931C973A2037D3FC83A4D7D775D05E4
Example path:
HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
There’s also a Reddit comment suggesting Microsoft has started restoring the certs and that admins can check this via Advanced Hunting in Defender:
DeviceRegistryEvents
| where RegistryKey contains "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
or RegistryKey contains "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
| where ActionType == "RegistryKeyCreated"
| where Timestamp > datetime(2026-05-03T04:00:00)
| project Timestamp, DeviceName, ActionType, InitiatingProcessFileName
| order by Timestamp desc
On an affected device, this can also be checked with:
certutil -store AuthRoot | findstr -i "digicert"
Could become an annoying day for admins if this spreads
https://t.co/VflLyFgssp
On 2/2 #AnyDesk announced a breach resulting in stolen source code and certificates, and has revoked all web portal passwords and recommends users change their password. PANW customers are not currently affected. Read AnyDesk's statement here: https://t.co/3Y8tNNZ15W
@epp654 Είναι για μην λερώνουν τον αγκώνα τους ή το εκάστοτε ρούχο που φοράνε; Νομίζουν ότι κουβαλάνε το κράνος της μοτοσυκλέτας τους ίσως; Ποτε δεν θα μάθουμε.