Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1553.002 Code Signing |
GroupGALLIUM | GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC. |
| T1553.002 Code Signing |
GroupKimsuky | Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper. |
| T1553.002 Code Signing |
GroupPatchwork | Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies. |
| T1553.002 Code Signing |
GroupAPT41 | APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations. |
| T1553.002 Code Signing |
GroupmenuPass | menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures. |
| T1553.002 Code Signing |
GroupFIN6 | FIN6 has used Comodo code-signing certificates. |
| T1553.002 Code Signing |
GroupFIN7 | FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls. |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1553.002 Code Signing |
GroupScattered Spider | Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC. |
| T1553.002 Code Signing |
GroupMoses Staff | Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection. |
| T1553.002 Code Signing |
GroupOilRig | OilRig has signed its malware with stolen certificates. |
| T1553.002 Code Signing |
GroupSuckfly | Suckfly has used stolen certificates to sign its malware. |
| T1553.002 Code Signing |
GroupSaint Bear | Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH." |
| T1553.002 Code Signing |
GroupLeviathan | Leviathan has used stolen code signing certificates to sign malware. |
| T1553.002 Code Signing |
GroupTA505 | TA505 has signed payloads with code signing certificates from Thawte and Sectigo. |
| T1553.002 Code Signing |
GroupMirrorFace | MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed. |
| T1553.002 Code Signing |
GroupMedusa Group | Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools. |
| T1553.002 Code Signing |
GroupDarkhotel | Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them. |
| T1553.002 Code Signing |
GroupLuminousMoth | LuminousMoth has signed their malware with a valid digital signature. |
| T1553.002 Code Signing |
GroupWinnti Group | Winnti Group used stolen certificates to sign its malware. |
| T1553.002 Code Signing |
GroupLazarus Group | Lazarus Group has digitally signed malware and utilities to evade detection. |
| T1553.002 Code Signing |
GroupSilence | Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot). |
| T1553.002 Code Signing |
GroupCopyKittens | CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared. |
| T1553.002 Code Signing |
GroupWizard Spider | Wizard Spider has used Digicert code-signing certificates for some of its malware. |
| T1553.002 Code Signing |
GroupMolerats | Molerats has used forged Microsoft code-signing certificates on malware. |
| T1553.002 Code Signing |
GroupPROMETHIUM | PROMETHIUM has signed code with self-signed certificates. |
| T1553.002 Code Signing |
GroupDaggerfly | Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments. |
| T1553.002 Code Signing |
GroupTeamPCP | TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.