Code Signing Policy Modification

T1553.006

Sub-technique of T1553 Subvert Trust Controls.View on attack.mitre.org

About this technique

Adversaries may modify code signing policies to enable execution of unsigned or self-signed code. Code signing provides a level of authenticity on a program from a developer and a guarantee that the program has not been tampered with. Security controls can include enforcement mechanisms to ensure that only valid, signed code can be run on an operating system.

Some of these security controls may be enabled by default, such as Driver Signature Enforcement (DSE) on Windows or System Integrity Protection (SIP) on macOS. Other such controls may be disabled by default but are configurable through application controls, such as only allowing signed Dynamic-Link Libraries (DLLs) to execute on a system. Since it can be useful for developers to modify default signature enforcement policies during the development and testing of applications, disabling of these features may be possible with elevated permissions.

Adversaries may modify code signing policies in a number of ways, including through use of command-line or GUI utilities, Modify Registry, rebooting the computer in a debug/recovery mode, or by altering the value of variables in kernel memory. Examples of commands that can modify the code signing policy of a system include bcdedit.exe -set TESTSIGNING ON on Windows and csrutil disable on macOS. Depending on the implementation, successful modification of a signing policy may require reboot of the compromised system. Additionally, some implementations can introduce visible artifacts for the user (ex: a watermark in the corner of the screen stating the system is in Test Mode). Adversaries may attempt to remove such artifacts.

To gain access to kernel memory to modify variables related to signature checks, such as modifying g_CiOptions to disable Driver Signature Enforcement, adversaries may conduct Exploitation for Privilege Escalation using a signed, but vulnerable driver.

Detection rules0

Rules on DetectionCode tagged with T1553.006.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software3

Campaigns0

None recorded.

Procedure examples5

Groups2

Used byProcedure example
GroupAPT39

APT39 has used malware to turn off the RequireSigned feature which ensures only signed DLLs can be run on Windows.

GroupTurla

Turla has modified variables in kernel memory to turn off Driver Signature Enforcement after exploiting vulnerabilities that obtained kernel mode privileges.

Software3

Used byProcedure example
MalwareBlackEnergy

BlackEnergy has enabled the TESTSIGNING boot configuration option to facilitate loading of a driver component.

MalwareHikit

Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component.

MalwarePandora

Pandora can use CVE-2017-15303 to disable Windows Driver Signature Enforcement (DSE) protection and load its driver.

References8

  1. Apple Disable SIP Open source
    Apple. (n.d.). Disabling and Enabling System Integrity Protection. Retrieved April 22, 2021.
  2. F-Secure BlackEnergy 2014 Open source
    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.
  3. FireEye HIKIT Rootkit Part 2 Open source
    Glyer, C., Kazanciyan, R. (2012, August 22). The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 2). Retrieved November 17, 2024.
  4. GitHub Turla Driver Loader Open source
    TDL Project. (2016, February 4). TDL (Turla Driver Loader). Retrieved April 22, 2021.
  5. Microsoft DSE June 2017 Open source
    Microsoft. (2017, June 1). Digital Signatures for Kernel Modules on Windows. Retrieved April 22, 2021.
  6. Microsoft TESTSIGNING Feb 2021 Open source
    Microsoft. (2021, February 15). Enable Loading of Test Signed Drivers. Retrieved April 22, 2021.
  7. Microsoft Unsigned Driver Apr 2017 Open source
    Microsoft. (2017, April 20). Installing an Unsigned Driver during Development and Test. Retrieved April 22, 2021.
  8. Unit42 AcidBox June 2020 Open source
    Reichel, D. and Idrizovic, E. (2020, June 17). AcidBox: Rare Malware Repurposing Turla Group Exploit Targeted Russian Organizations. Retrieved March 16, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.