2018/03/07 by Kristián Kozák, Kozák, Kristián, Bum Jun Kwon +5
Computer Science · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #Cybercrime and Law Enforcement Studies #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Spam and Phishing Detection
paper · pdf · doi:10.48550/arxiv.1803.02931
openalex publication_date 2018/03/07 · openalex created_date 2022/10/06 · openalex updated_date 2026/07/28
Recent measurements of the Windows code-signing certificate ecosystem have\nhighlighted various forms of abuse that allow malware authors to produce\nmalicious code carrying valid digital signatures. However, the underground\ntrade that allows miscreants to acquire such certificates is not well\nunderstood. In this paper, we illuminate two aspects of this trade. First, we\ninvestigate 4 leading vendors of Authenticode certificates, we document how\nthey conduct business, and we estimate their market share. Second, we collect a\ndata set of recently signed malware and we use it to study the relationships\namong malware developers, malware families and the certificates. We also use\ninformation from the black market to fingerprint the certificates traded and to\nidentify when the are likely used to sign malware in the wild. Using these\nmethods, we document a shift in the methods that malware authors employ to\nobtain valid digital signatures. While prior studies have reported the use of\ncode-signing certificates that had been compromised or obtained directly from\nlegitimate Certification Authorities, we observe that, in 2017, these methods\nhave become secondary to purchasing certificates from underground vendors. We\nalso find that the need to bypass platform protections such as Microsoft\nDefender SmartScreen plays a growing role in driving the demand for\nAuthenticode certificates. Together, these findings suggest that the trade in\ncertificates issued for abuse represents an emerging segment of the underground\neconomy.\n