Signed to Deceive: The Return of FiveSys Rootkits
How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits.

Digitally-Signed Rootkits are Back – A Look at FiveSys and Companions
How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It
In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits. One standout example: FiveSys, a rootkit signed with legitimate digital certificates, has reemerged alongside a growing family of stealthy, persistent threats.
At Alpha Cyber, we’ve mapped the infrastructure supporting these threats and what we found is alarming:
Infrastructure Map Overview:
Multiple C2 servers routed through anonymizing layers
Code-signing certificates abused from legitimate vendors
Shared tooling and payload patterns across companion malware
Geotargeting tactics to focus attacks on specific regions
Persistent mechanisms that survive reboots and evade traditional AV
These aren’t just random infections, they’re highly targeted, stealth operations with the backing of well-resourced adversaries.
Why It Matters to You:
If your organization relies solely on conventional endpoint protection, you’re at serious risk. Digitally-signed rootkits like FiveSys are designed to slip through unnoticed. Once embedded, they provide full kernel-level access, ideal for espionage, data exfiltration, and sabotage.
IOCS to Block:
Angdao[.]com[.]cnwww[.]newsensation.com[.]cn
Our Response:
We offer advanced threat detection, infrastructure mapping, and threat hunting services to:
Detect rootkits and kernel-level intrusions
Reverse-engineer attacker infrastructure
Proactively hunt for related IOCs and malware variants
Protect your systems before they’re compromised.
Contact us today for a custom threat assessment or schedule a consultation.



