According to an IT company, an advertisement on a Russian underground forum is selling one or two valid code signing certificates every week to help malware evade detection by antivirus software.
Digital certificates are used to sign programs, in order to validate their integrity and that they have not been altered for malicious purposes.
This method has usually been effective for validating legitimate code that has been installed on a machine and there is no malicious intent. However, cybercriminals have managed to find ways to use legitimate certificates to sign malware.
The Russians made thousands of dollars in two months. According to a blog post by SenseCy, the digital certificate first published the offer about two months ago and continues to add updates on a regular basis.
The first certificate was sold for around $1,000 / €787, and the next day, the ad contained a message saying it could provide up to two digital certificates for signing EXE files.
The advertisement on the forum made it clear to the public that the certificates it sells are not drivers, but also only work on executable EXE, DLL and JAR files, as well as for DOC.
SenseCy reports that during monitoring over a two-month period, approximately seven to ten certificates have been sold.
The origin of the certificates has not yet been determined. The company warns of a potential abundance of signed malware in the near future, which likely originates from the DigiNotar breach that occurred in 2011 and ended with the company's bankruptcy.

