Peaches Posted June 23, 2010 Report Share Posted June 23, 2010 <h1></h1>Malware: certified trustworthy F-Secure say that virus authors successfully use various tricks to obtain valid digital signatures or certificates for their programs. The most reliable method is to trick a Certificate Authority into issuing a code signing certificate. It seems that this has become just as easy as obtaining a valid SSL server certificate – a valid email address is sufficient. Internet frauds and criminals also use such services as Digital River, which sign software for their customers. Virus authors can also misuse stolen certificates or private keys to sign their own software. Various versions of the Adrenalin, Ursnif and ZeuS families of botnets are said to contain functions for reading the relevant data from developers' infected PCs. However, so far F-Secure has not found any malware that actually uses a stolen key in its malware database. Full story - http://www.h-online.com/security/news/item/Malware-certified-trustworthy-1027066.html Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.