Hunting Certified Imposters

No ratings

Presented at SecTor 2024 by

2023 and 2024 have seen an increase in signed Windows App Package abuse by a variety of threat actors including FIN7, FakeBat, Batloader, Rhadamanthys and others. Microsoft took a step in the right direction when they introduced the modern installer format (.MSIX) which requires packages to be signed with a valid code signing certificate to sideload them successfully. Yet, thanks to a seemingly endless supply of code signing certificates, this doesn't appear to be a huge barrier for adversaries to overcome which begs the question: "How hard is it to get certified?".This talk will dive into the code signing certificate malware ecosystem and demonstrate how adversaries are exploiting loopholes in validation requirements to sign their malicious installer packages (and how you can make them pay, literally).