HomeSecuritySymantec How malware extracts digital certificates

Symantec How malware extracts digital certificates

In recent times, we have heard of many malware attacks in which cybercriminals sign with valid digital certificates in an attempt to ensure that their work goes unnoticed. Symantec have analyzed how attackers manage to steal private keys with their malware.

Experts explain that it is almost impossible for a hacker without the necessary tools to get inside a computer to check if it has private keys of valid digital certificates.

Ωστόσο, ένα κακόβουλο λογισμικό μπορεί να ανακτήσει εύκολα τα πολύτιμα δεδομένα μιας μολυσμένης συσκευής.

The most common malware used for this job are the following:

Backdoor.Beasty, Infostealer.Snifula, Downloader.Parshell, Trojan.Spyeye, W32.Cridex, W32.Qakbot, Infostealer.Shiz, Trojan.Carberp and Trojan.Zbot (γνωστό και σαν ZeuS).

Τα περισσότερα από αυτά έχουν εντοπιστεί σε υπολογιστές που βρίσκονται στις Ηνωμένες Πολιτείες.

Πώς όμως το κακόβουλο λογισμικό εξάγει τα ψηφιακά πιστοποιητικά;

Usually, digital certificates are stored in the Windows certificate store. From there, they can be exported using functions such as PFXExportCertStoreEx. To export a private key, the EXPORT_PRIVATE_KEYS option is used.

This function exports the information to a .Pfx file, which is often encrypted by cybercriminals.

Most malware start stealing digital certificates as soon as the computer boots, but some wait for the intruder's command.

Once they gain access to private keys, cybercriminals can sign their malicious works, using programs that are freely available such as “Sign Tool.”

In order to prevent the theft of private keys, companies are required to keep them in a network that is separate from the company's internal network. Additionally, developers should use test certificates for new applications.

Symantec endpoint

Generally, it is not recommended that digital certificates and private keys be stored on computers. They should be locked in a secure place such as IC cards, USB tokens, or separate security hardware. If this is not possible, they should at least be archived and protected with a strong password.

Finally, experts advise companies to avoid storing them on portable media as much as possible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS