Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
The Government of Malaysia has had a code signing certificate stolen and used to sign malware.
The breach was discovered after researchers at security firm F-Secure found a trojan signed by the certificate owned from the Government.
Officials from the Malaysian Agricultural Research and Development Institute told F-Secure the certificate was stolen "quite some time ago".
The signed trojan would not be flagged by risk mitigation warnings that alert users if unsigned applications were downloaded from the internet.
“In some of these cases, the certificate has been created by the criminals just for the purpose for signing malware. In other cases they steal code signing certificates (and their passphrases) so they can sign code as someone else,” CTO Mikko Hypponen said.
“It's not that common to find a signed copy of malware. It's even rarer that it's signed with an official key belonging to a government.”
The trojan spread via malicious PDF files that exploited Adobe Reader 8. The malware downloaded components from a server called worldnewsmagazines.org signed by www.esupplychain.com.tw.
Problems facing the PKI trust model have been demonstrated in a string of recent hacks of some of the 600 certificate authorities that are entrusted to sign digital certificates.
Copyright © SC Magazine, Australia
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.