Microsoft Trusted Signing service abused to code-sign malware
ID: 595e6e9c-743b-5636-b12c-6c2c61cff450
STIX ID: report--595e6e9c-743b-5636-b12c-6c2c61cff450
Feed Name: Bleeping Computer
Threat Score
Cybercriminals have been observed abusing Microsoft’s Trusted Signing service to obtain short-lived (three-day) code-signing certificates and sign malware samples, enabling them to evade security warnings and improve file reputation; multiple active campaigns (including crypto-theft and info-stealer activity) have been linked to these signed binaries, and Microsoft reports active monitoring, certificate revocation, and account suspension to mitigate the abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
