ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1553.002×

28 examples

TechniqueUsed byProcedure example
T1553.002
Code Signing
GroupGALLIUM

GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC.

T1553.002
Code Signing
GroupKimsuky

Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper.

T1553.002
Code Signing
GroupPatchwork

Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies.

T1553.002
Code Signing
GroupAPT41

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.

T1553.002
Code Signing
GroupmenuPass

menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures.

T1553.002
Code Signing
GroupFIN6

FIN6 has used Comodo code-signing certificates.

T1553.002
Code Signing
GroupFIN7

FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
GroupScattered Spider

Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC.

T1553.002
Code Signing
GroupMoses Staff

Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection.

T1553.002
Code Signing
GroupOilRig

OilRig has signed its malware with stolen certificates.

T1553.002
Code Signing
GroupSuckfly

Suckfly has used stolen certificates to sign its malware.

T1553.002
Code Signing
GroupSaint Bear

Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH."

T1553.002
Code Signing
GroupLeviathan

Leviathan has used stolen code signing certificates to sign malware.

T1553.002
Code Signing
GroupTA505

TA505 has signed payloads with code signing certificates from Thawte and Sectigo.

T1553.002
Code Signing
GroupMirrorFace

MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed.

T1553.002
Code Signing
GroupMedusa Group

Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.

T1553.002
Code Signing
GroupDarkhotel

Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them.

T1553.002
Code Signing
GroupLuminousMoth

LuminousMoth has signed their malware with a valid digital signature.

T1553.002
Code Signing
GroupWinnti Group

Winnti Group used stolen certificates to sign its malware.

T1553.002
Code Signing
GroupLazarus Group

Lazarus Group has digitally signed malware and utilities to evade detection.

T1553.002
Code Signing
GroupSilence

Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot).

T1553.002
Code Signing
GroupCopyKittens

CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared.

T1553.002
Code Signing
GroupWizard Spider

Wizard Spider has used Digicert code-signing certificates for some of its malware.

T1553.002
Code Signing
GroupMolerats

Molerats has used forged Microsoft code-signing certificates on malware.

T1553.002
Code Signing
GroupPROMETHIUM

PROMETHIUM has signed code with self-signed certificates.

T1553.002
Code Signing
GroupDaggerfly

Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments.

T1553.002
Code Signing
GroupTeamPCP

TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.