SECURITY researchers say multiple threat groups, including Iran’s Charming Kitten offshoot Subtle Snail, are deploying malware signed with certificates from SSL[.]com, a Houston-based certificate authority. According to Check Point Software and Prodaft researchers, UNC1549 has used SSL[.]com code-signing certificates to target European organisations with new binaries for backdoors and infostealers.
The researchers note that the certificates were issued to a Dutch company called Insight Digital B.V., and that other binaries used by UNC1549 carried certificates issued to Sweden-based entities RGC Digital AB and Sevenfeet Software AB. They warn that SSL[.]com certificates can make malicious code appear legitimate, leading to a drastic decrease in detections and samples remaining undetectable by multiple malware engines.
Dark Reading reports that Check Point found three of the four SSL[.]com certificates observed in the latest UNC1549 activity were still valid, underscoring ongoing red flags for certificate authorities and defenders.