Sub-technique of T1553 Subvert Trust Controls.View on attack.mitre.org
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.
Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform.
Code signing certificates may be used to bypass security policies that require signed code to execute on a system.
Rules on DetectionCode tagged with T1553.002.
| Rule | Level | Log source |
|---|---|---|
| Potential Secure Deletion with SDelete | medium | windows / NULL |
| Used by | Procedure example |
|---|---|
| GroupAPT41 | APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations. |
| GroupCopyKittens | CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared. |
| GroupDaggerfly | Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments. |
| GroupDarkhotel | Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them. |
| GroupFIN6 | FIN6 has used Comodo code-signing certificates. |
| GroupFIN7 | FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls. |
| GroupGALLIUM | GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC. |
| GroupKimsuky | Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor has been signed with valid certificates to evade detection by security tools. |
| MalwareAppleJeus | AppleJeus has used a valid digital signature from Sectigo to appear legitimate. |
| MalwareBackConfig | BackConfig has been signed with self signed digital certificates mimicking a legitimate software company. |
| MalwareBandook | Bandook was signed with valid Certum certificates. |
| MalwareBazar | Bazar has been signed with fake certificates including those appearing to be from VB CORPORATE PTY. LTD. |
| MalwareBlack Basta | The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives. |
| MalwareBLINDINGCAN | BLINDINGCAN has been signed with code-signing certificates such as CodeRipper. |
| MalwareBOOKWORM | BOOKWORM has used valid legitimate digital signatures and certificates to evade detection. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022. During the 3CX Supply Chain Attack, AppleJeus used a code signing certificate to digitally sign the malicious software with an expiration date set to October 2022. This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe, also signed with the same digital certificate. |
| CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads. |
| CampaignC0015 | For C0015, the threat actors used DLL files that had invalid certificates. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection. |
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature. |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used legitimate, signed binaries such as `inkform.exe` or `ExcelRepairToolboxLauncher.exe` for follow-on execution of malicious DLLs through DLL search order hijacking in RedDelta Modified PlugX Infection Chain Operations. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.