New Malware Signed With Stolen Government Certificate
Trailrunner7 writes "Security researchers claim that malware spreading via malicious PDF files is signed with a valid certificate stolen from the Government of Malaysia, in just the latest evidence that scammers are using gaps in the security of digital certificates to help spread malicious code. The malware, identified by F-Secure as a Trojan horse program dubbed Agent.DTIW, was detected in a signed Adobe PDF file by the company's virus researchers recently. The malicious PDF was signed using a valid digital certificate for mardi.gov.my, the Agricultural Research and Development Institute of the Government of Malaysia. According to F-Secure, the Government of Malaysia confirmed that the certificate was legitimate and had been stolen 'quite some time ago.'"
Also, who the hell actually installs software just because the Malaysian government signs it?
It's not "who", it's "what". As in "What operating system trusts signed <foo> more than unsigned equivalent?" As in "All of them."
A signed cert opens doors that most users aren't even aware of. Add to that (in this case) an existing remote arbitrary code execution exploit in unpatched vulnerable versions of Acrobat Reader 8, and you've got a lovely recipe for malware drive-by installation.
Welcome to the Panopticon. Used to be a prison, now it's your home.
Isn't this precisely what certificate revocation lists are for?
"Before criticizing someone, first walk a mile in his shoes. Then, you'll be a mile away... and you'll have his shoes."