Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungRate Limiting: The Traffic Cop Your API Needs(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungI Built the MVP First. Then I Wrote the README.(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungHow to add a loading screen with a progress bar in Godot 4(20.09.2026 um 14:52 Uhr)
Sichere ProgrammierungCanada is about to break your scheduler(20.09.2026 um 14:59 Uhr)
Sichere ProgrammierungWhat Does an AI Automation Agency Actually Do?(20.09.2026 um 15:00 Uhr)
Sichere ProgrammierungRate Limiting: The Traffic Cop Your API Needs(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungI Built the MVP First. Then I Wrote the README.(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungHow to add a loading screen with a progress bar in Godot 4(20.09.2026 um 14:52 Uhr)
Sichere ProgrammierungCanada is about to break your scheduler(20.09.2026 um 14:59 Uhr)
Sichere ProgrammierungWhat Does an AI Automation Agency Actually Do?(20.09.2026 um 15:00 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

P wave of malicious code signing - Yuta Sawabe & Rintaro Koike (NTT Security Holdings)

Reagiere als Erste:r — dein Feedback zählt!

Author: Virus Bulletin - Bewertung: 0x - Views:1

Presented at the VB2024 conference in Dublin, 2 - 4 October 2024.
↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/slides/Slides-P-wave-of-malicious-code-signing.pdf
↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/papers/P-wave-of-malicious-code-signing.pdf
→ Details: https://www.virusbulletin.com/conference/vb2024/abstracts/p-wave-malicious-code-signing/

✪ PRESENTED BY ✪

• Yuta Sawabe (NTT Security Holdings)
• Rintaro Koike (NTT Security Holdings)

✪ ABSTRACT ✪

These days, regardless of being related to APT or crime, many malware and malicious files are code-signed. This is largely due to the existence of code-signing certificate sellers that play a role in the ecosystem. Instead of preparing code-signing certificates themselves, attackers can buy them.

We took a serious look at the interesting behaviour of code-signing certificate sellers. Prior to selling the certificates to their customers, they had signed to benign software using the certificates and posted the signed software to online malware scanning services to test whether the certificates were judged as expected (not only valid, but also benign). Such inspections occurred long before the certificates were sold and abused by attackers.

We collected the files posted by these sellers and harvested code-signing certificate information that could be abused in the future. This was a kind of experiment to predict the future. As a result, we succeeded in predicting future abuse cases. This could be an effective approach against code-signed malware and malicious files.

In this presentation we will first introduce the code-signing certificate sellers and their ecosystem. Then, we will illustrate their interesting inspections with a detailed timeline. Finally, we will present the approach we have developed and evaluate its effectiveness.

This presentation will allow the audience to understand the ecosystem related to the code-signing market for threat actors. It will also help the audience to understand certificates sellers' interesting approaches and the overall picture. This knowledge will allow SOCs, IRs, CSIRTs, and other personnel to take proactive measures against code-signed malware and malicious files.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten P wave of malicious code signing - Yuta Sawabe & Rintaro Koike (NTT Security Holdings)

Thematisch verwandte Begriffe: wave, malicious, code, signing · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93956 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by thi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick