zerofox logo
Advisories

ZeroFox Intelligence Flash Report - New Extended Validation Code Signing Service Advertised

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - New Extended Validation Code Signing Service Advertised

Product Serial: F-2024-07-03a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on a recent post in the dark web forum exploit, advertising a new extended validation code signing service.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On June 30, 2024, untested actor “enryu” advertised a new extended validation (EV) code signing service on the primarily Russian-speaking dark web forum exploit.
  • According to the advertisement, illicit validation certificates can be purchased, which allow malicious webpages to bypass security protocols such as SmartScreen, Windows User Account Control, and Windows Defender, as well as some antivirus (AV) software provided by third parties such as Kaspersky, Avast, and Malwarebytes.
  • Illicit validation certificates offer cyber threat actors the ability to augment a wide array of malicious activities, such as the deploying of disruptive malware to target networks, enhanced social engineering attacks, or data theft resulting in operational disruption, extortion or fraud.
  • Given the versatility offered by initial network access, services such as these are very likely to appeal to a wide range of threat actors with varying intents and motivations, leading to their continued development, competitiveness, and innovation.

Tags: tlp:clear,  dark web,  phishing & fraud