Feeds

Crooks, think your Trojan looks legit? This one has a DIGITAL CERTIFICATE

CA defends issuing digital seal to Brazilian swindlers

Internet Security Threat Report 2014

Updated Security researchers have discovered a banking Trojan that comes with its own built-in digital certificate.

The Brazilian banking password-sniffer was signed with a valid digital certificate issued by DigiCert, MalwareBytes reports. DigiCert responded promptly to inquiries by El Reg to confirm it had a had pulled the offending certificate, which it said had been issued to a legally registered business.

The firm said the crooks behind the banking Trojan used a certificate that had been issued to a real software company called "Buster Paper Comercial Ltda". DigiCert said that Buster Paper was properly registered and it was only following general industry practice in issuing a digital certificate, as a statement by the firm explains.

DigiCert has conducted a thorough review of this matter and can confirm that the certificate was validated and issued in accordance with industry guidelines.

At the time that the code signing certificate was issued, Buster Paper Comercial Ltda was a legally registered business as confirmed through the Brazilian Ministerio da Fazenda: Cadastro Sincronizado Nacional.

DigiCert’s Terms of Use clearly state that malware is not an accepted type of activity for which our certificates can be used. As soon as DigiCert learned of the misuse of the certificate, it was immediately revoked.

Malware endorsed by a digital certificate is not unprecedented - Stuxnet and Flame were both signed using digital certificates - but the appearance of the same tactic much further down the food chain in more everyday nasties is still very bad news.

Around 15 months ago malware using a private signing certificate belonging to the Malaysian government to bypass warnings displayed by many operating systems and security software when end users attempt to run untrusted applications appeared on the web. The latest threat represents the same sort of problem but features a digital certificate issued to a suspicious company rather than a legitimate government.

Crooks who obtained the Buster Paper Comercial Ltda digital seal used this authority to digitally sign an item of malware that poses as a PDF document supposedly containing an invoice. The trick was designed to fool recipients at targeted firms into opening the document and becoming infected.

The malware is ultimately designed to plant a key-logger that lifts any entered banking login credentials from infected machines. The Trojan, detected as Spyware.Banker.FakeSig by MalwareBytes, is designed to download additional components from egnyte.com. The abuse of the cloud storage firm's systems appears to be entirely incidental*.

Three months ago last November, the same type of Trojan was found, this time signed by "Buster Assistencia Tecnica Electronica Ltda" using a certificate also issued by DigiCert. How that would have appeared in a victim's inbox is illustrated in a contemporaneous write-up of the attack by Threat Expert.com here.

Both of the offending certificates have been revoked but this still leaves a number of questions outstanding, according to MalwareBytes.

"What we have here is a total abuse of hosting services, digital certificates and repeated offences from the same people," writes Jerome Segura, a security researcher at Malwarebytes. "Clearly, if digital certificates can be abused so easily, we have a big problem on our hands.

"Even if a file is digitally signed, it does not guarantee that it’s safe to use. A lot of potentially unwanted applications can use a digital certificate and, of course, malware can too (with a valid or revoked certificate)," he adds.

A full write-up of the attack - including screenshots of the offending digital certificates - can be found on Malwarebytes blog here.

Brazil is something of a global hotspot for banking Trojans and related malware, so innovations by local VXers presumably trying to gain an edge over competitors isn't wholly surprising. ®

Update

Kris Lahiri, Egnyte's security chief, contacted El Reg to say:

* It was recently brought to our attention that a customer of Egnyte had a piece of malware hosted on our system that may have been shared publicly. We take these situations very seriously... we followed the standard process of suspending the account, locking access and filing a report with the IC3 (a partnership between the FBI and NWCCC).

Even though a user may upload an infected file to their account in Egnyte, it is completely prevented from infecting any other file within that account.

Secure remote control for conventional and virtual desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
prev story

Whitepapers

Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.