Skip to main content

Dirtbags dressed up malware as legit app using Sony crypto-certs

  • December 10, 2014
  • 2 replies
  • 2 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
We can expect a few of these illegal certificates to show up shortly I suppose in the crims attempt to foist malware on unsuspecting users, a bit like this which was reported yesterday -
 
 

Code-signing certificate revoked in wake of discovery

 
 
 
By Iain Thomson, 10 Dec 2014
 
 
 
EXCERPT
 
 
 
These certificate were apparently taken from Sony Pictures servers, which were comprehensively ransacked by hackers at the end of November, and leaked online.
 
It's believed the infiltrators used a version of Destover to attack Sony's network. And it appears the stolen digital certs were used to sign another build of Destover on Friday, which then ended up in the wild over the weekend.
 
When Windows examines an executable, it looks to see if the program has been signed by a recognized, trusted developer before running the code. As far as the operating system was concerned, the signed Destover was legit.
 
"The stolen Sony certificates (which were also leaked by the attackers) can be used to sign other malicious samples," Kaspersky warned on Tuesday.
 
Full Article
 
 
 

2 replies

shorTcircuiT
Gold VIP
  • Gold VIP
  • December 10, 2014
The break-in that keeps on giving..... headaches that is.  Thanks Jasper!

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
I think we are going to be seeing repercussions from that attack for quite a while yet, there is almost a new story per day being reported due to it.