New Malware Signed With Stolen Government Certificate
Trailrunner7 writes "Security researchers claim that malware spreading via malicious PDF files is signed with a valid certificate stolen from the Government of Malaysia, in just the latest evidence that scammers are using gaps in the security of digital certificates to help spread malicious code. The malware, identified by F-Secure as a Trojan horse program dubbed Agent.DTIW, was detected in a signed Adobe PDF file by the company's virus researchers recently. The malicious PDF was signed using a valid digital certificate for mardi.gov.my, the Agricultural Research and Development Institute of the Government of Malaysia. According to F-Secure, the Government of Malaysia confirmed that the certificate was legitimate and had been stolen 'quite some time ago.'"
We talking days? weeks? months? years? And why wasnt it immediately flagged as stolen?
The article makes no mention of the signing certificate being revoked. Why hasn't the signing certificate been revoked?
a download site for Stuxnet.
I'd like to make it a GNU Project .
Yours In Novosibirsk,
K. Trout, C.T.O.
So the gap is "the secret key must be kept secret"? I don't see that as a digital certificate failing. It's also the reason we have revocation lists.
It is copyright infringement.
Don't fight for your country, if your country does not fight for you.
Isn't this precisely what certificate revocation lists are for?
"Before criticizing someone, first walk a mile in his shoes. Then, you'll be a mile away... and you'll have his shoes."
Relax, don't do it. When you want to go to it.
I don't read good.
How exactly do you go about stealing a digital certificate? Can you revoke the cert after the event? What happens to legitimate sites using the stolen cert?
Now I'll make some more $$ off of the dumb-asses who get their shit ass WinBlowz computers owned by going to infected pron links. Score!!!!
Dear AC, don't worry.The mod who modded you down can hardly be blamed. He doesn't know about Dr. M, and he probably doesn't speak Bahasa Malaysia neither. So something was whooshing over her head.
When faced with a virus that none of the existing tools detect, I open up Process Explorer, tell it to verify signatures, and then check for any currently loaded objects with a signature that can't be verified (or no signature). It's just one part of the investigation but it's certainly a good start.
This increase in stolen certs is troubling.
The right question: why the fuck does the Agricultural Research and Development Institute of the Government of Malaysia even need a CA??
http://www.f-secure.com/weblog/archives/mardi-cert_malaysian.PNG
How is this a 'Valid certificate' again ?