Digital Certificates- When the Chain of Trust is Broken

June 5, 2018

Written by

Intezer

As stated in a previous blog entry, it is common for malware authors to sign malicious files with “legitimate” digital certificates in order to bypass security products. In some cases, certificates are stolen or faked by advanced threat actors using complex techniques. But sometimes, certificate theft is as simple as legally purchasing a certificate from a CA under a false identity.

The latter is a CA-side error, where the CA fails to properly verify the client’s identity. This constitutes a breach in the chain of trust that PKI signing relies on, which raises two questions:

1. How far down the chain can the trust be breached?
2. Are there any truly trustworthy CAs?

To answer these questions, we picked a test dataset of about 5000 files from our database: 50% of which are trusted and 50% malicious, all having valid digital signatures. Our goal was to find out which certificates are being used for each group at every level- root, intermediate and end-user.

Comparing the root CAs used in trusted and malicious files, we can see how often even major CAs are compromised:


In fact, the only major root CA that hasn’t been compromised is Microsoft. We believe this is because Microsoft certificates are used only in Microsoft products and threat actors do not have the opportunity to legally buy them.

It is worth noting that there have been a few documented cases of highly advanced threat actors faking Microsoft certificates. One example is Lazarus’ usage of self signed certificates, all named “Microsoft Code Signing PCA”. These certificates are considered valid by Sigcheck and similar tests, because these tests don’t necessarily validate the entire chain of trust. However, you can see that there is only one signer rather than the usual chain. (example)

Analyzing intermediate certificates shows similar results to root certificates. These are the intermediate certificates that appear a significant amount of times in trusted files, but not in malicious ones:

Microsoft Code Signing PCA148
Microsoft Windows Production PCA 2011100
Intel External Issuing CA 7B20
Microsoft Windows Third Party Component CA 201213
As you can see, these certificates are issued by Microsoft and Intel, and are indeed used only in these companies’ products.

On the other hand, when it comes to end-user certificates, there are many more certificates that appear only in trusted files. Some examples of certificate names are “Adobe Systems Incorporated”, “Symantec Corporation”, “McAfee Inc.”, “CyberLink”, “Dropbox Inc”, “Apple Inc”. and “LENOVO”.

As a general rule, it seems that it is extremely difficult for threat actors to acquire certificates from legitimate, established technological companies.

To conclude, it is quite common for threat actors to legally purchase certificates from legitimate CAs, and even the greatest root CAs aren’t safe. However, it is much rarer to see malware use a certificate from well-established corporations such as Microsoft, Intel and Adobe, whose certificates are only used for their own products.

Seeing as we can’t blindly trust digital signatures, security policies should integrate solutions that address the concern of stolen or fake certificates. Intezer Analyze™ offers one such solution, using Code Intelligence, our unique technology based on code reuse detection, revealing attacks that could otherwise bypass existing security tools.

For instance, let’s examine this sample of Innaput, which has a valid certificate issued by Comodo:

Intezer Analyze™ recognizes the sample for what it is.

We invite you to try Intezer Analyze for yourself!

Intezer

Count on Intezer AI SOC to triage, investigate and respond to every alert at unmatched speed and accuracy.

In this article

Share article

Related Articles

Alert Triage

AI SOC

3 min

We let a fruit fly brain triage 12,716 real SOC Alerts. Here is what happened.

On behalf of people who run SOCs, we explore how a fly brain triages alerts compared with a boring linear model you could train in eleven seconds.

AI SOC

4 min

The impact of the AI SOC: Intezer joins the Cybersecurity Awesomeness Podcast

Intezer's Field CISO and CMO join the Cybersecurity Awesomeness Podcast to explain what the AI SOC is, how it cuts false positives, and why analysts end up more empowered.

AI SOC

CISO

MDR

4 min

Financial services need to rethink the MDR model

MDR providers investigate only about 40% of alerts. Learn why financial institutions are rethinking MDR renewals and what full alert coverage requires in 2026.