New Threat Actor Fraudulently Buys Digital Certificates to Spread Malware
#1
Bug 
Quote:Researchers have identified a new threat actor that is using impersonation fraud to purchase digital certificates that are then used for the spread of malware.
 
Security firm ReversingLabs identified a bad actor that deceives certificate authorities into selling them legitimate digital certificates by impersonating company executives, according to a blog post by chief architect and co-founder Tomislav Pericin. Once purchased, the bad actor sells the certificates on the black market for digitally signing malicious files, mainly adware, he said.
 
“Certificates are valuable resources to threat actors, as their mere presence can reduce the chance of early malware detection,” he wrote. “This is particularly true for financially motivated actors.”
ReversingLabs used public threat intelligence data to reconstruct the timeline of a fraudulent purchase of digital certifications, including the impersonation of a legitimate entity. That included proof that the bad actors provided the purchased certificates to a cybercrime group and that they were used to spread malware via signed malicious files, according to the post.

Read more here: https://threatpost.com/threat-actor-buys...re/148345/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Google Chrome 149.0.7827.200/201
Google Chrome 149....harlan4096 — 08:26
Brave 1.91.180 (Jun 26, 2026)
Release Notes v1.9...harlan4096 — 08:24
Adobe Acrobat Reader DC 2026.001.21691
Adobe Acrobat Read...harlan4096 — 08:22
PowerToys v0.100.2
Release v0.100.2 ...harlan4096 — 08:21
GeForce Game Ready Driver 452.06
NVIDIA 580.173.02 Li...harlan4096 — 08:18

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>