New Threat Actor Fraudulently Buys Digital Certificates to Spread Malware

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,148
Researchers have identified a new threat actor that is using impersonation fraud to purchase digital certificates that are then used for the spread of malware.

Security firm ReversingLabs identified a bad actor that deceives certificate authorities into selling them legitimate digital certificates by impersonating company executives, according to a blog post by chief architect and co-founder Tomislav Pericin. Once purchased, the bad actor sells the certificates on the black market for digitally signing malicious files, mainly adware, he said.

“Certificates are valuable resources to threat actors, as their mere presence can reduce the chance of early malware detection,” he wrote. “This is particularly true for financially motivated actors.”
ReversingLabs used public threat intelligence data to reconstruct the timeline of a fraudulent purchase of digital certifications, including the impersonation of a legitimate entity. That included proof that the bad actors provided the purchased certificates to a cybercrime group and that they were used to spread malware via signed malicious files, according to the post.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top