Code Signing

T1553.002

Sub-technique of T1553 Subvert Trust Controls.View on attack.mitre.org

About this technique

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform.

Code signing certificates may be used to bypass security policies that require signed code to execute on a system.

Detection rules1

Rules on DetectionCode tagged with T1553.002.

Sigma1

RuleLevelLog source
Potential Secure Deletion with SDeletemediumwindows / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups28

Show 4 more

Software53

Show 29 more

Campaigns8

Procedure examples89

Groups28

Used byProcedure example
GroupAPT41

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.

GroupCopyKittens

CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared.

GroupDaggerfly

Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments.

GroupDarkhotel

Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them.

GroupFIN6

FIN6 has used Comodo code-signing certificates.

GroupFIN7

FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls.

GroupGALLIUM

GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC.

GroupKimsuky

Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper.

View all 28 groups examples

Software53

Used byProcedure example
MalwareAnchor

Anchor has been signed with valid certificates to evade detection by security tools.

MalwareAppleJeus

AppleJeus has used a valid digital signature from Sectigo to appear legitimate.

MalwareBackConfig

BackConfig has been signed with self signed digital certificates mimicking a legitimate software company.

MalwareBandook

Bandook was signed with valid Certum certificates.

MalwareBazar

Bazar has been signed with fake certificates including those appearing to be from VB CORPORATE PTY. LTD.

MalwareBlack Basta

The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives.

MalwareBLINDINGCAN

BLINDINGCAN has been signed with code-signing certificates such as CodeRipper.

MalwareBOOKWORM

BOOKWORM has used valid legitimate digital signatures and certificates to evade detection.

View all 53 software examples

Campaigns8

Used byProcedure example
Campaign3CX Supply Chain Attack

Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022. During the 3CX Supply Chain Attack, AppleJeus used a code signing certificate to digitally sign the malicious software with an expiration date set to October 2022. This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe, also signed with the same digital certificate.

CampaignAPT41 DUST

APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads.

CampaignC0015

For C0015, the threat actors used DLL files that had invalid certificates.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection.

CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used legitimate, signed binaries such as `inkform.exe` or `ExcelRepairToolboxLauncher.exe` for follow-on execution of malicious DLLs through DLL search order hijacking in RedDelta Modified PlugX Infection Chain Operations.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle.

References4

  1. EclecticLightChecksonEXECodeSigning Open source
    Howard Oakley. (2020, November 16). Checks on executable code in Catalina and Big Sur: a first draft. Retrieved September 21, 2022.
  2. Securelist Digital Certificates Open source
    Ladikov, A. (2015, January 29). Why You Shouldn’t Completely Trust Files Signed with Digital Certificates. Retrieved March 31, 2016.
  3. Symantec Digital Certificates Open source
    Shinotsuka, H. (2013, February 22). How Attackers Steal Private Keys from Digital Certificates. Retrieved March 31, 2016.
  4. Wikipedia Code Signing Open source
    Wikipedia. (2015, November 10). Code Signing. Retrieved March 31, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.