GovRAT, the malware-signing-as-a-service platform in the underground

Security Experts at InfoArmor discovered GovRAT, a malware-signing-as-a-service platform that is offered to APT groups in the underground.

In the past, I have explained why digital certificates are so attractive for crooks and intelligence agencies, one of the most interesting uses is the signature of malware code in order to fool antivirus. Naturally, digital certificates are becoming a precious commodity in the underground ecosystem, many operators in the black markets started this lucrative business.

A few weeks ago experts at IBM Security X-Force  observed the offer of certificates in the Dark Web with a model of sale they called CaaS (Certificates as a service). Cybercriminals would use the Dark Web for selling high-grade code certificates -which they have obtained from trusted certificate authorities- to anyone that is interested in purchasing them.

The sale of code signing certificates has increased considerably over the past few months, a trend confirmed also by a recent research analysis conducted by  the threat intelligence firm InfoArmor.

The research has given rise to a case in which a hacker tricked a legitimate certificate authority into issuing digital certificates for malware before offering a cyber-espionage tool called GovRAT.

GovRAT a hacking platform that allows the malware creation, it comes bundled with digital certificates for code signing. The same digital certificates were initially offered for sale on the black marketplace TheRealDeal Market hosted on the Tor network. GovRAT was offered for sale at 1.25 Bitcoin, but experts observed the creator is now selling it privately.

GovRAT Digital certificatesGovRAT Digital certificates

The GovRAT tool digitally signs malicious code with code-signing tools such as Microsoft SignTool, WinTrust, and Authenticode technology. The experts consider that final customer for GovRAT are APT groups targeting political, diplomatic and military employees of more than 15 governments worldwide.

The strains of malware analyzed by the researchers at InfoArmor were signed individually with different digital certificates.

InfoArmor reported also that seven banks, some in the US, and 30 defence contractors have also been targeted by the GovRAT.  It has been estimated that more than 100 organizations have been hit by malware created by the GovRAT platform since early 2014.

Which is the price for code-signing digital certificates?

Experts at InfoArmor found the precious commodities on many underground black markets, they are offered for sale at a price between $600-$900 depending on the CA that issued them. It is quite easy to find code-signing digital certificates issued by Comodo, GoDaddy and Thawte. It is clear that digital certificates could be revoked by the CA, but as explained by numerous sellers the event is rare and often companies are very slow in invalidating them.

“[The buyers are] blackhats (mostly state-sponsored), malware developers,” Andrew Komarov, CIO at InfoArmor, told El Reg. “It is pretty professional audience, as typical script kiddies and cybercriminals don’t need such stuff. It is used in APTs, organised for targeted and stealth attacks. The appearance of such services on the blackmarket allow [hackers] to perform them much more easily, rather like Stuxnet.” “It is a pretty specific niche of modern underground market,” “It can’t be very big, as the number of certificates is pretty limited, and it is not easy to buy them, but according to our statistics, the number of such services is significantly growing.”

Stolen or fake certificates are a prerogative of state-sponsored attacks, they were used in numerous offensives including the Stuxnet and the Sony hack, the experts explained that cyber criminals are gaining digital certificates through resellers.

“Bad actors buy digital certificates through resellers, where the due diligence of customers is pretty poor,” Komarov explained. “They provide fake names, or fake information about the author and purpose on why they need this certificate, and receive it. After they have received such certificates, they trade it on the blackmarket for malware developers, allowing them to create signed malware for further APT in several minutes.”

InfoArmor reported the case of certs4you.org, a website offering malware-signing-as-a-service with prepared digital certificates.    One such service ran from a website called certs4you.org before the domain was suspended.

Let me suggest reading the report on GovRAT published by InfoArmor.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – GovRAT, code-signing digital certificates)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Victoria’s Secret ‘s website offline following a cyberattack

Victoria’s Secret took its website offline after a cyberattack, with experts warning of rising threats…

16 hours ago

China-linked APT41 used Google Calendar as C2 to control its TOUGHPROGRESS malware

Google says China-linked group APT41 controlled malware via Google Calendar to target governments through a…

19 hours ago

New AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.

GreyNoise researchers warn of a new AyySSHush botnet compromised over 9,000 ASUS routers, adding a…

1 day ago

Czech Republic accuses China’s APT31 of a cyberattack on its Foreign Ministry

The Czech government condemned China after linking cyber espionage group APT31 to a cyberattack on…

2 days ago

New PumaBot targets Linux IoT surveillance devices

PumaBot targets Linux IoT devices, using SSH brute-force attacks to steal credentials, spread malware, and…

2 days ago

App Store Security: Apple stops $2B in fraud in 2024 alone, $9B over 5 years

Apple blocked over $9B in fraud in 5 years, including $2B in 2024, stopping scams…

2 days ago