www.darkreading.com 9/26/2025, 7:00:44 PM · via preferred

Iranian State Hackers Use SSL.com Certificates to Sign Malware

SECURITY researchers say multiple threat groups, including Iran’s Charming Kitten offshoot Subtle Snail, are deploying malware signed with certificates from SSL[.]com, a Houston-based certificate authority. According to Check Point Software and Prodaft researchers, UNC1549 has used SSL[.]com code-signing certificates to target European organisations with new binaries for backdoors and infostealers.

The researchers note that the certificates were issued to a Dutch company called Insight Digital B.V., and that other binaries used by UNC1549 carried certificates issued to Sweden-based entities RGC Digital AB and Sevenfeet Software AB. They warn that SSL[.]com certificates can make malicious code appear legitimate, leading to a drastic decrease in detections and samples remaining undetectable by multiple malware engines.

Dark Reading reports that Check Point found three of the four SSL[.]com certificates observed in the latest UNC1549 activity were still valid, underscoring ongoing red flags for certificate authorities and defenders.

View full article

Article by CyberSIXT