HomeSecurityEmsisoft: Hackers are forging our certificates to compromise networks

Emsisoft: Hackers are forging our certificates to compromise networks

Cybercriminals are exploiting Emsisoft's credibility by forging code signing certificates in order to gain access to the security products used by its customers, bypassing all defenses.

Emsisoft: Hackers are forging our certificates to compromise networks

Code signing certificates act as digital signatures, confirming that the application has not been modified since the publisher signed it. This allows users, software, and operating systems to confidently validate its authenticity.

Hackers are trying to exploit this opportunity by creating fake certificates that appear to be associated with a trusted organization, although they are actually fake.

Emsisoft recently issued a warning to its customers, warning them that hackers used an executable program with a fake company certificate as part of their attack. The attackers hoped that this would trick the customer into believing that any detections were false positives, thus allowing their malware to run undetected .

See also: Windows 11: Fixes one of the most annoying bugs

Although the attack was unsuccessful thanks to Emsisoft's security software, which detected and blocked the file based on its invalid signature, they are still warning their customers about similar malicious attempts.

Spoofing Emsisoft for remote access

According to Emsisoft, the threat actor likely infiltrated the device either by breaching RDP or by taking possession of credentials belonging to an employee of the targeted organization.

After connecting to the endpoint, the attackers proceeded to install MeshCentral – an open source that is usually considered safe due to its valid and beneficial purpose.

However, the MeshCentral executable file was digitally signed with a fake Emsisoft certificate that purportedly came from the “Emsisoft Server Trusted Network CA”.

Emsisoft chose not to disclose details about the executable file, but BleepingComputer revealed that it was named “smsse.exe” [VirusTotal], as seen below.

Emsisoft

When Emsisoft's security product scanned the file, it detected an invalid signature, which forced the software to mark it as "Unknown" and consequently remove it from distribution.

However, if an employee ignores this warning just because of the name of the digital signature, they may allow the application to run and grant a malicious actor full control of their device.

See also: Hyundai and Kia release patch for dangerous security flaw

With this remote access, malicious actors can bypass existing protections in order to spread throughout the network, leak sensitive data , and even deploy ransomware.

To ensure the security of your system, Emsisoft recommends that you verify that a file is genuine and safe before granting it permission to run. If you are unsure about the authenticity of an executable file, consult security vendors for further verification of its source.

See also: Hackers use Havoc as an alternative to Cobalt Strike

To prevent any potential breach or tampering of the Emsisoft product, the company encourages system administratorsto set a secure password for added protection.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS