UPDATED 08:00 EDT / FEBRUARY 22 2018

INFRA

Research finds that counterfeit security certificates are now being custom-created

One of the fundamentals of internet security, secure certificates, is under attack.

Researchers at threat intelligence firm Recorded Future Inc. said today that they’ve found criminal groups selling both code signing certificates and domain name registrations with accompanying SSL certificates.

The research notes that previously it was believed that security certificates circulating in the underground had been stolen from legitimate owners. But now they’ve been discovered to be custom-created for specific buyers upon request and registered using stolen corporate identities. As a result, the researchers claim, traditional network security appliances are much less effective at recognizing them.

“It’s been generally accepted that security certificates circulating in the criminal underground were stolen from legitimate owners prior being used in nefarious campaigns,” Andrei Barysevich, director of advanced collection at Recorded Future, told SiliconANGLE. “However, our most recent analysis indicates this is not the case. We have confirmed – with a high degree of certainty – that counterfeit certificates are created for specific buyers, per request only, and registered using stolen corporate identities.”

Barysevich added that the firm believe the legitimate business owners are completely unaware that their data was or is being used in these illicit activities. “While we don’t anticipate the widespread use of counterfeit credentials, we do believe that sophisticated actors with specific targets will continue to rely on fake code signing and SSL certificates as a part of their operations,” he said.

The economics of the dubious certificate business, detailed in the report, is both interesting and disturbing at the same time. The researchers found that the most affordable version of a code signing certificate costs $299, but the most comprehensive Extended Validation certificate with a SmartScreen reputation rating is listed for $1,599. The starting price of a domain name registration with EV SSL certificate is $349.

All the certificates offered are issued by reputable companies, including Comodo, Thawte and Symantec, and “have proved to be extremely effective in malware obfuscation.” That leads the researchers to conclude that “legitimate business owners are unaware that their data was used in the illicit activities.”

Image: Pixabay

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.