Author: Virus Bulletin - Bewertung: 0x - Views:1
Presented at the VB2024 conference in Dublin, 2 - 4 October 2024.
↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/slides/Slides-P-wave-of-malicious-code-signing.pdf
↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/papers/P-wave-of-malicious-code-signing.pdf
→ Details: https://www.virusbulletin.com/conference/vb2024/abstracts/p-wave-malicious-code-signing/
✪ PRESENTED BY ✪
• Yuta Sawabe (NTT Security Holdings)
• Rintaro Koike (NTT Security Holdings)
✪ ABSTRACT ✪
These days, regardless of being related to APT or crime, many malware and malicious files are code-signed. This is largely due to the existence of code-signing certificate sellers that play a role in the ecosystem. Instead of preparing code-signing certificates themselves, attackers can buy them.
We took a serious look at the interesting behaviour of code-signing certificate sellers. Prior to selling the certificates to their customers, they had signed to benign software using the certificates and posted the signed software to online malware scanning services to test whether the certificates were judged as expected (not only valid, but also benign). Such inspections occurred long before the certificates were sold and abused by attackers.
We collected the files posted by these sellers and harvested code-signing certificate information that could be abused in the future. This was a kind of experiment to predict the future. As a result, we succeeded in predicting future abuse cases. This could be an effective approach against code-signed malware and malicious files.
In this presentation we will first introduce the code-signing certificate sellers and their ecosystem. Then, we will illustrate their interesting inspections with a detailed timeline. Finally, we will present the approach we have developed and evaluate its effectiveness.
This presentation will allow the audience to understand the ecosystem related to the code-signing market for threat actors. It will also help the audience to understand certificates sellers' interesting approaches and the overall picture. This knowledge will allow SOCs, IRs, CSIRTs, and other personnel to take proactive measures against code-signed malware and malicious files.
SOCIAL SHARE CARD GENERATOR