TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Help Net Security

DigiCert breached via malicious screensaver file

Sinisa Markovic · 2 days ago · Read original ↗

ATT&CK techniques detected

4 predictions
T1588.003Code Signing Certificates
89%
“reports submitted by community members linking them to malware, while 16 were identified during the company ’ s internal investigation. the rest were pulled as a precaution, as customer control could not be confirmed. all were revoked within 24 hours of discovery, and pending ord…”
T1588.003Code Signing Certificates
79%
“##ization codes for orders that were approved but pending delivery. ” while several delivery attempts were blocked, the attacker ultimately compromised two support systems, gaining access to internal tools. the first compromised system was identified and contained within 24 hours…”
T1195.002Compromise Software Supply Chain
41%
“##ization codes for orders that were approved but pending delivery. ” while several delivery attempts were blocked, the attacker ultimately compromised two support systems, gaining access to internal tools. the first compromised system was identified and contained within 24 hours…”
T1195Supply Chain Compromise
31%
“##ization codes for orders that were approved but pending delivery. ” while several delivery attempts were blocked, the attacker ultimately compromised two support systems, gaining access to internal tools. the first compromised system was identified and contained within 24 hours…”

Summary

A targeted social engineering attack against DigiCert’s support channel led to the compromise of internal systems and the unauthorized issuance of EV Code Signing certificates. DigiCert is a global Certificate Authority (CA) providing digital trust services, specializing in TLS/SSL certificates, PKI management, and IoT security. According to DigiCert’s incident report, a threat actor contacted the support team via a customer chat channel and delivered a malicious ZIP file disguised as a customer screenshot, which contained … More

The post DigiCert breached via malicious screensaver file appeared first on Help Net Security.