Cryptographic Certificates are the Biggest Nightmare
ID: 9a930afc-fca8-559f-85f7-dd74002cd017
STIX ID: report--9a930afc-fca8-559f-85f7-dd74002cd017
Feed Name: Zscaler Security Research Blog
The report describes how Flame/related malware abused stolen Microsoft code-signing certificates and ClickOnce deployment to present malicious executables as legitimate Windows/Microsoft updates, bypass or spoof UAC warnings, and potentially enable silent installation when a certificate exists in a user's Trusted Publishers list; it highlights UI deception techniques (truncated hostnames, ClickOnce dialog text) and advises checking and removing unrecognized Trusted Publisher certificates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
