Code-signing certificates are supposed to help authenticate the identity of software publishers, and provide cryptographic assurance that a signed piece of software has not been altered or tampered with. Both of these qualities make stolen or ill-gotten code-signing certificates attractive to cybercriminal groups, who prize their ability to add stealth and longevity to malicious software. This post is a deep dive on “ Megatraffer ,” a veteran Russian hacker who has practically cornered the underground marke
One of Megatraffer’s ads on an English-language cybercrime forum.
A review of Megatraffer’s posts on Russian crime forums shows this user began peddling individual stolen code-signing certs in 2015 on the Russian-language forum Exploit , and soon expanded to selling certificates for cryptographically signing applications and files designed to run in Microsoft Windows , Java , Adobe AIR , Mac and Microsoft Office .