UPDATED 08:00 EDT / FEBRUARY 22 2018

INFRA

Research finds that counterfeit security certificates are now being custom-created

One of the fundamentals of internet security, secure certificates, is under attack.

Researchers at threat intelligence firm Recorded Future Inc. said today that they’ve found criminal groups selling both code signing certificates and domain name registrations with accompanying SSL certificates.

The research notes that previously it was believed that security certificates circulating in the underground had been stolen from legitimate owners. But now they’ve been discovered to be custom-created for specific buyers upon request and registered using stolen corporate identities. As a result, the researchers claim, traditional network security appliances are much less effective at recognizing them.

“It’s been generally accepted that security certificates circulating in the criminal underground were stolen from legitimate owners prior being used in nefarious campaigns,” Andrei Barysevich, director of advanced collection at Recorded Future, told SiliconANGLE. “However, our most recent analysis indicates this is not the case. We have confirmed – with a high degree of certainty – that counterfeit certificates are created for specific buyers, per request only, and registered using stolen corporate identities.”

Barysevich added that the firm believe the legitimate business owners are completely unaware that their data was or is being used in these illicit activities. “While we don’t anticipate the widespread use of counterfeit credentials, we do believe that sophisticated actors with specific targets will continue to rely on fake code signing and SSL certificates as a part of their operations,” he said.

The economics of the dubious certificate business, detailed in the report, is both interesting and disturbing at the same time. The researchers found that the most affordable version of a code signing certificate costs $299, but the most comprehensive Extended Validation certificate with a SmartScreen reputation rating is listed for $1,599. The starting price of a domain name registration with EV SSL certificate is $349.

All the certificates offered are issued by reputable companies, including Comodo, Thawte and Symantec, and “have proved to be extremely effective in malware obfuscation.” That leads the researchers to conclude that “legitimate business owners are unaware that their data was used in the illicit activities.”

Image: Pixabay

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU