{"id":5494,"date":"2025-09-30T05:57:48","date_gmt":"2025-09-30T05:57:48","guid":{"rendered":"https:\/\/signmycode.com\/blog\/?p=5494"},"modified":"2025-09-30T05:57:49","modified_gmt":"2025-09-30T05:57:49","slug":"iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware","status":"publish","type":"post","link":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware","title":{"rendered":"Iranian Hackers Exploit SSL.com Certificates to Sign Malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Digital certificates are designed to create trust. But what happens when hackers take advantage of gaps in trust? Reports show that Iranian state-sponsored hackers have been using valid SSL.com certificates to sign malware. This means they could make their malware undetectable and, therefore, more dangerous.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-incident-signed-malware-in-the-wild\"><a><\/a>The Incident: Signed Malware in the Wild<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Check Point Software and Prodaft revealed that an Iranian group tracked as UNC1549, aka Subtle Snail, Smoke Sandstorm, and Nimbus Manticore, had put malware in the wild signed with SSL.com code-signing certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These code-signing certificates gave the malware an air of legitimacy and reduced detection rates for many antivirus engines, which simply trust &#8220;signed&#8221; code. The problem security tools faced was that the signed code was malicious, and the tool trusted it as safe because it was signed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-the-hackers-exploited-ssl-com\">How the Hackers Exploited SSL.com?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Multiple investigations claimed the signed code had been issued to a list of suspicious businesses, <strong>such as:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Insight Digital B.V. &#8211; Netherlands<\/li>\n\n\n\n<li>RGC Digital AB &#8211; Sweden<\/li>\n\n\n\n<li>Sevenfeet Software AB &#8211; Sweden<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The domains all contained the same header, &#8220;Under Construction&#8221; stock images, and there were no contact details listed. These are strong warning signs that a certificate authority (CA) should have detected when issuing the signed code. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Check Point stated that<\/em><\/strong> they believed the companies were either designed front companies created by the actors or that they were fraudulent identities created in the likeness of real businesses. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless, the fact that the certificates were issued suggests there are questions surrounding SSL.com&#8217;s vetting process.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-signed-malware-is-so-dangerous\">Why Signed Malware Is So Dangerous?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Signed binaries generate a considerable risk:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Lower Detection Rates:<\/strong> Malware appears to be normal software.<\/li>\n\n\n\n<li><strong>Bypasses Trust Checks:<\/strong> Many organizations specifically whitelist signed executables.<\/li>\n\n\n\n<li><strong>Persistence: <\/strong>Actors can stay operational longer before detection.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, UNC1549 used the certificates to deploy back doors and infostealer malware against European organizations, but the risk is global.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-ssl-com-s-response-comes-into-focus\">SSL.com\u2019s Response Comes into Focus<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>When Dark Reading reached out to SSL.com<\/em><\/strong>, they first talked with an AI chatbot that simply summarized the inquiry, providing no genuine response. Then Dark Reading created a support ticket, which generated another AI-driven reply that was also vague.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the time of publishing, SSL.com hadn&#8217;t provided any direct response from their security or communications teams. <strong><em>This lack of transparency, plus the fact that some certificates are still valid, raises significant and warranted questions about SSL.com as a CA had they been able to respond to the abuse.<\/em><\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-history-repeats-a-lesson-from-symantec\"><a><\/a>History Repeats: A Lesson from Symantec<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is not the first time a CA is in question for abuse; back in 2017 Google revoked trust from all Symantec certificates after discovering they had mistakenly issued 30,000+ certificates. As a result, Symantec was forced to sell its PKI business to DigiCert.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If SSL.com does not take considerable steps to improve identity validation and incident response processes, it risks losing the trust of the industry as Symantec did.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-defending-against-signed-malware\"><a><\/a>Defending Against Signed Malware<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While companies cannot influence CA practices, they can enact a risk mitigation plan:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Import Indicators of Compromise (IOCs):<\/strong> Take Check Point&#8217;s file hashes and domains, and import it into SIEM\/EDR solutions<\/li>\n\n\n\n<li><strong>Analyze Certificate Metadata:<\/strong> Flag any binaries that do not have a signer matching that of the software publisher<\/li>\n\n\n\n<li><strong>Monitor Certificate Revocations:<\/strong> Look at the CRLs\/OCSP and block binaries using revoked certs.<\/li>\n\n\n\n<li><strong>Implement Zero Trust Execution Policies: <\/strong>Don&#8217;t just simply rely on digital signatures; use behavioral monitoring instead.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-does-this-mean-for-pki-security\"><a><\/a>What Does This Mean for PKI Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This case provides clear insight into a key weakness in the PKI ecosystem: certificate authorities are a prime target for abuse. Weak vetting combined with over-reliance on automation generates a large gap into which threat actors will insert themselves.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Invalidated malware is not just a detection challenge; it is a trust challenge. If organizations cannot trust the certificates that they depend on, the entire digital trust model begins to break down.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\"><a><\/a>Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To safeguard your enterprise, you should leverage what are considered highly trusted certificate providers that can demonstrate an established record of security, compliance, trust, and validation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Industry leaders such as <a href=\"https:\/\/signmycode.com\/digicert-code-signing\">DigiCert Code Signing Certificates<\/a> and <a href=\"https:\/\/signmycode.com\/sectigo-code-signing\">Sectigo Code Signing Certificates<\/a> perform more thorough validation and revocation processes, more in line with industry standards, making them less susceptible to abuse. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Start protecting your software supply chain with <a href=\"https:\/\/signmycode.com\/digicert-software-trust-manager\">DigiCert Software Trust Manager<\/a> &#8211; certified to be trusted around the world.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital certificates are designed to create trust. But what happens when hackers take advantage of gaps in trust? Reports show that Iranian state-sponsored hackers have been using valid SSL.com certificates to sign malware. This means they could make their malware undetectable and, therefore, more dangerous. The Incident: Signed Malware in the Wild Check Point Software&hellip; <a class=\"more-link\" href=\"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware\">Read More <span class=\"screen-reader-text\">Iranian Hackers Exploit SSL.com Certificates to Sign Malware<\/span><\/a> <\/p>\n","protected":false},"author":1,"featured_media":5496,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,458],"tags":[884,883],"class_list":["post-5494","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-code-signing-updates","category-cyber-security","tag-signed-malicious-code","tag-ssl-com-code-signing-certificates","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Iranian Hackers Exploit SSL.com Code Signing Certificates to Sign Malware<\/title>\n<meta name=\"description\" content=\"SSL.com Code Signing Certificates made the malicious code look like legitimate software programs. Threat actors pay a very low price to SSL.com to sign their malicious code.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Iranian Hackers Exploit SSL.com Code Signing Certificates to Sign Malware\" \/>\n<meta property=\"og:description\" content=\"SSL.com Code Signing Certificates made the malicious code look like legitimate software programs. Threat actors pay a very low price to SSL.com to sign their malicious code.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware\" \/>\n<meta property=\"og:site_name\" content=\"SignMyCode - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-30T05:57:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-30T05:57:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/ssl-code-signing-to-sign-malware.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"912\" \/>\n\t<meta property=\"og:image:height\" content=\"453\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware\",\"name\":\"Iranian Hackers Exploit SSL.com Code Signing Certificates to Sign Malware\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ssl-code-signing-to-sign-malware.webp\",\"datePublished\":\"2025-09-30T05:57:48+00:00\",\"dateModified\":\"2025-09-30T05:57:49+00:00\",\"description\":\"SSL.com Code Signing Certificates made the malicious code look like legitimate software programs. Threat actors pay a very low price to SSL.com to sign their malicious code.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#primaryimage\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ssl-code-signing-to-sign-malware.webp\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ssl-code-signing-to-sign-malware.webp\",\"width\":912,\"height\":453,\"caption\":\"SSL.com Allows to Sign Malicious Code\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Iranian Hackers Exploit SSL.com Certificates to Sign Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"name\":\"SignMyCode - Blog\",\"description\":\"Code Signing News, Updates\",\"publisher\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\",\"name\":\"SignMyCode.com\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"width\":135,\"height\":86,\"caption\":\"SignMyCode.com\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Iranian Hackers Exploit SSL.com Code Signing Certificates to Sign Malware","description":"SSL.com Code Signing Certificates made the malicious code look like legitimate software programs. Threat actors pay a very low price to SSL.com to sign their malicious code.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware","og_locale":"en_US","og_type":"article","og_title":"Iranian Hackers Exploit SSL.com Code Signing Certificates to Sign Malware","og_description":"SSL.com Code Signing Certificates made the malicious code look like legitimate software programs. Threat actors pay a very low price to SSL.com to sign their malicious code.","og_url":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware","og_site_name":"SignMyCode - Blog","article_published_time":"2025-09-30T05:57:48+00:00","article_modified_time":"2025-09-30T05:57:49+00:00","og_image":[{"width":912,"height":453,"url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/ssl-code-signing-to-sign-malware.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware","url":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware","name":"Iranian Hackers Exploit SSL.com Code Signing Certificates to Sign Malware","isPartOf":{"@id":"https:\/\/signmycode.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#primaryimage"},"image":{"@id":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#primaryimage"},"thumbnailUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/ssl-code-signing-to-sign-malware.webp","datePublished":"2025-09-30T05:57:48+00:00","dateModified":"2025-09-30T05:57:49+00:00","description":"SSL.com Code Signing Certificates made the malicious code look like legitimate software programs. Threat actors pay a very low price to SSL.com to sign their malicious code.","breadcrumb":{"@id":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#primaryimage","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/ssl-code-signing-to-sign-malware.webp","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2025\/09\/ssl-code-signing-to-sign-malware.webp","width":912,"height":453,"caption":"SSL.com Allows to Sign Malicious Code"},{"@type":"BreadcrumbList","@id":"https:\/\/signmycode.com\/blog\/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malware#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/signmycode.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Iranian Hackers Exploit SSL.com Certificates to Sign Malware"}]},{"@type":"WebSite","@id":"https:\/\/signmycode.com\/blog\/#website","url":"https:\/\/signmycode.com\/blog\/","name":"SignMyCode - Blog","description":"Code Signing News, Updates","publisher":{"@id":"https:\/\/signmycode.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/signmycode.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/signmycode.com\/blog\/#organization","name":"SignMyCode.com","url":"https:\/\/signmycode.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","width":135,"height":86,"caption":"SignMyCode.com"},"image":{"@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/comments?post=5494"}],"version-history":[{"count":1,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5494\/revisions"}],"predecessor-version":[{"id":5495,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5494\/revisions\/5495"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media\/5496"}],"wp:attachment":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media?parent=5494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/categories?post=5494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/tags?post=5494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}