In an unusual move, Metamorfo abuses legitimate, signed Windows binaries to load the malicious code.
Source: Threadpost