Signed keylogger/infostealer masquerading as a Webroot security product ("DefenderPlug", ProductName "BrowseSecure") while its embedded manifest simultaneously claims to be Microsoft.Windows.RuntimeBroker. Signed with a valid SSL.com EV Code Signing certificate issued to "Osh Spetsstroy LLC" (KG), serial 3D7B3B375FE1434665CBF43EF2119168, signed 2026-08-06 11:39:56 UTC, NOT revoked as of 2026-08-07. Imports GetAsyncKeyState, GetForegroundWindow, SetTimer and GetDlgItemTextA (keystroke capture incl. reading foreign window controls). Writes to %APPDATA%\DefenderPlug, exfiltrated to https://wcz2ps4v-8443.use.devtunnels.ms/. Part of a fake Windows-update package that also deploys a persistent