DigiCert Hacked via Weaponized Screensaver File to Obtain EV Code Signing Certificates
ID: fae717da-17ac-5614-8235-978c9ee7b501
STIX ID: report--fae717da-17ac-5614-8235-978c9ee7b501
Feed Name: cybersecurityNews.com
**Executive summary:** A threat actor compromised DigiCert support analysts via a malicious .scr inside a ZIP delivered through a Salesforce chat, enabling theft and activation of 60 EV Code Signing certificates that were used to sign and distribute the Zhong Stealer malware; DigiCert revoked all affected certificates, identified seven attacker IPs, linked 27 certs to the attacker, and implemented UI/API fixes, stricter MFA controls, suspended analyst accounts, and canceled pending code-signing orders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
