HomeinetLet’s Encrypt: Malware distribution with HTTPS protection

Let's Encrypt: Malware distribution with HTTPS protection

It's only been a month since certificate authority Let's Encrypt launched a beta program distributing free HTTPS certificates to the public, and hackers have begun abusing the service to distribute malware through seemingly secure websites.security virus HTTPS

In December, the security company Trend Micro detected certain users in Japan who had been infected by a malicious server that hosted the Angler Exploit Kit. The trojans allowed hackers to gain remote access to the infected systems without the owners knowing.

The company reports that the malvertisers used a technique called domain shadowing, which allows them to gain access to a trusted domain (for example the main website of a bank). Thus they can redirect users to their own server, which conceals the activity of password interception.

To make the deception attempt more believable, they use a subdomain that is protected by Let’s Encrypt’s free security certificate (HTTPS).

In the case of the research by Trend Micro, the attackers hosted a malicious advertisement that appeared to be related to a legitimate domain.

The company states that this was possible because Let’s Encrypt checks domains against the Google safe browsing API before issuing new certificates. This naturally does not stop intruders from obtaining a new certificate and creating subdomains with malicious software under the protection of a legitimate domain.

According to the Trend Micro report, the incident highlights the potential issues of the Let’s Encrypt service and calls on the company to be ready to revoke certificates that have been misused.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS