
Security certificates are intended to instill trust in users . Traditional antivirus software typically relies on databases that use certificates to detect whether software downloaded or run on a machine contains any malicious content. However, if it is signed by a legitimate authority, malicious software could go unnoticed. This is what some attackers rely on.
The same process applies to websites. Security certificates demonstrate a website's credentials, including its ability to secure and encrypt data transmitted between a client and the browser, and these certificates are issued by a Certificate Authority (CA). Certificates also come with an expiration date and must be renewed relatively frequently.
Cybercriminals, on the other hand, can use these certificates to spread malware and trick victims into visiting malicious domains that appear trustworthy.
Certificates can give malicious actors the ability to masquerade as trusted sources. There have been cases of certificate theft in the past, for reasons such as selling surveillance tools or directly spying on users, and now researchers have found that attackers are pretending to be legitimate business executives to purchase certificates online.
According to Tomislav Pericin, co-founder of ReversingLabs, certificate and identity theft can sometimes be “interconnected” in the trade of illegal security certificates.
In a recently discovered case being monitored by the security firm, a malicious actor pretends to be a business executive in order to purchase and later sell certificates on malware development forums.
The attacker first conducts research to select suitable, viable targets. Once they find their target, they register domains associated with a legitimate business. The attacker then requests a code signing certificate, which requires less verification – and therefore all the information needed to target the market is already there.
In order to validate their stolen identity, the legal existence of the business is checked against government or trusted third-party databases, the website domain is verified via email, and then a simple, automated callback process is typically performed to validate the businesses.
The attacker has now successfully impersonated a business and is in possession of a code signing certificate that is available for sale.
ReversingLabs believes that the attacker, or hacking , behind this scam has used the same tactic on at least a dozen companies.
