Install Root Certificate

T1553.004

Sub-technique of T1553 Subvert Trust Controls.View on attack.mitre.org

About this technique

Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers. Root certificates are used in public key cryptography to identify a root certificate authority (CA). When a root certificate is installed, the system or application will trust certificates in the root's chain of trust that have been signed by the root certificate. Certificates are commonly used for establishing secure TLS/SSL communications within a web browser. When a user attempts to browse a website that presents a certificate that is not trusted an error message will be displayed to warn the user of the security risk. Depending on the security settings, the browser may not allow the user to establish a connection to the website.

Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system. Adversaries have used this technique to avoid security warnings prompting users when compromised systems connect over HTTPS to adversary controlled web servers that spoof legitimate websites in order to collect login credentials.

Atypical root certificates have also been pre-installed on systems by the manufacturer or in the software supply chain and were used in conjunction with malware/adware to provide Adversary-in-the-Middle capability for intercepting information transmitted over secure TLS/SSL communications.

Root certificates (and their associated chains) can also be cloned and reinstalled. Cloned certificate chains will carry many of the same metadata characteristics of the source and can be used to sign malicious code that may then bypass signature validation tools (ex: Sysinternals, antivirus, etc.) used to block execution and/or uncover artifacts of Persistence.

In macOS, the Ay MaMi malware uses /usr/bin/security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /path/to/malicious/cert to install a malicious certificate as a trusted root certificate into the system keychain.

Detection rules12

Rules on DetectionCode tagged with T1553.004.

Sigma10

RuleLevelLog source
Cisco Crypto Commandshighcisco / NULL
Root Certificate Installed From Susp Locationshighwindows / process_creation
New Root Certificate Installed Via CertMgr.EXEmediumwindows / process_creation
New Root Certificate Installed Via Certutil.EXEmediumwindows / process_creation
Root Certificate Installed - PowerShellmediumwindows / ps_script
Suspicious Package Installed - Linuxmediumlinux / process_creation
Suspicious X509Enrollment - Process Creationmediumwindows / process_creation
Suspicious X509Enrollment - Ps Scriptmediumwindows / ps_script
Active Directory Certificate Services Denied Certificate Enrollment Requestlowwindows / NULL
Install Root Certificatelowlinux / process_creation

Splunk2

RuleTypeRiskData source
Attempt To Add Certificate To Untrusted StoreAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Registry Certificate AddedAnomalyNULLSysmon EventID 13

Groups0

None recorded.

Software5

Campaigns0

None recorded.

Procedure examples5

Software5

Used byProcedure example
Toolcertutil

certutil can be used to install browser root certificates as a precursor to performing Adversary-in-the-Middle between connections to banking websites. Example command: certutil -addstore -f -user ROOT ProgramData\cert512121.der.

MalwareDok

Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/filename.

Toolevilginx2

evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges.

MalwareHikit

Hikit installs a self-generated certificate to the local trust store as a root CA and Trusted Publisher.

MalwareRTM

RTM can add a certificate to the Windows store.

References5

  1. Kaspersky Superfish Open source
    Onuma. (2015, February 24). Superfish: Adware Preinstalled on Lenovo Laptops. Retrieved February 20, 2017.
  2. Operation Emmental Open source
    botconf eu. (2014, December 31). David Sancho - Finding Holes in Banking 2FA: Operation Emmental. Retrieved January 4, 2024.
  3. SpectorOps Code Signing Dec 2017 Open source
    Graeber, M. (2017, December 22). Code Signing Certificate Cloning Attacks and Defenses. Retrieved April 3, 2018.
  4. Wikipedia Root Certificate Open source
    Wikipedia. (2016, December 6). Root certificate. Retrieved February 20, 2017.
  5. objective-see ay mami 2018 Open source
    Patrick Wardle. (2018, January 11). Ay MaMi. Retrieved March 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.