Malware executables are being increasingly code-signed with three-day certificates using the Microsoft Trusted Signing service as threat actors seek to establish legitimacy and prevent thwarting by security systems, according to BleepingComputer.
With the usage of the service enabling validation of executables until the revocation of certificates, such a scheme has already been leveraged in Crazy Evil Traffers and Lumma Stealer attack campaigns, noted BleepingComputer and other cybersecurity researchers. More malicious actors have switched to Microsoft's service for code-signing malware due to convenience following ambiguous changes to Extended Validation certificates, said cybersecurity researcher and developer Squiblydoo. "For a long time, using EV certificates has been the standard, but Microsoft has announced changes to EV certificates... However, due to these potential changes and lack of clarity, just having a code-signing certificate may be adequate for attacker needs," Squiblydoo said. Meanwhile, Microsoft has confirmed having invalidated and suspended malicious certificates and accounts, respectively.
Wyden has formally requested the U.S. Government Accountability Office (GAO) to conduct a comprehensive inquiry into how agencies such as the FBI, DEA, ICE Homeland Security Investigations, and the Secret Service utilize these sophisticated surveillance technologies.
Explore how Agentic Identity and Access Management (IAM) helps organizations securely manage AI agents as governed non-human identities. Learn how identity, authentication, dynamic authorization, secure delegation, and real-time oversight can enable organizations to safely adopt and scale agentic AI while maintaining security and accountability.