UPDATED 08:00 EST / FEBRUARY 22 2018

INFRA

Research finds that counterfeit security certificates are now being custom-created

One of the fundamentals of internet security, secure certificates, is under attack.

Researchers at threat intelligence firm Recorded Future Inc. said today that they’ve found criminal groups selling both code signing certificates and domain name registrations with accompanying SSL certificates.

The research notes that previously it was believed that security certificates circulating in the underground had been stolen from legitimate owners. But now they’ve been discovered to be custom-created for specific buyers upon request and registered using stolen corporate identities. As a result, the researchers claim, traditional network security appliances are much less effective at recognizing them.

“It’s been generally accepted that security certificates circulating in the criminal underground were stolen from legitimate owners prior being used in nefarious campaigns,” Andrei Barysevich, director of advanced collection at Recorded Future, told SiliconANGLE. “However, our most recent analysis indicates this is not the case. We have confirmed – with a high degree of certainty – that counterfeit certificates are created for specific buyers, per request only, and registered using stolen corporate identities.”

Barysevich added that the firm believe the legitimate business owners are completely unaware that their data was or is being used in these illicit activities. “While we don’t anticipate the widespread use of counterfeit credentials, we do believe that sophisticated actors with specific targets will continue to rely on fake code signing and SSL certificates as a part of their operations,” he said.

The economics of the dubious certificate business, detailed in the report, is both interesting and disturbing at the same time. The researchers found that the most affordable version of a code signing certificate costs $299, but the most comprehensive Extended Validation certificate with a SmartScreen reputation rating is listed for $1,599. The starting price of a domain name registration with EV SSL certificate is $349.

All the certificates offered are issued by reputable companies, including Comodo, Thawte and Symantec, and “have proved to be extremely effective in malware obfuscation.” That leads the researchers to conclude that “legitimate business owners are unaware that their data was used in the illicit activities.”

Image: Pixabay

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.