Security News > 2023 > August > Hackers use VPN provider's code certificate to sign malware

The China-aligned APT group known as 'Bronze Starlight' was seen targeting the Southeast Asian gambling industry with malware signed using a valid certificate used by the Ivacy VPN provider.
According to SentinelLabs, which analyzed the campaign, the certificate belongs to PMG PTE LTD, a Singaporean vendor of the VPN product 'Ivacy VPN.'.
Exe malware sample was first found by security researcher MalwareHunterteam in May when they noted that the code-signing certificate was the same as one used for official Ivacy VPN installers.
An intriguing aspect of the observed attacks is using a code-singing certificate that belongs to PMG PTE LTD, the firm behind Ivacy VPN. In fact, the same certificate is used to sign the official Ivacy VPN installer linked to from the VPN provider's website.
If the certificate was stolen, security researchers are concerned about what else the threat actors had access to at the VPN provider.
PMG PTE LTD has not responded to this disclosure with a public statement, so the exact means by which the hackers gained access to the certificate remain unclear.
News URL
Related news
- Russia-Linked Hackers Target Kazakhstan in Espionage Campaign with HATVIBE Malware (source)
- Hackers leak configs and VPN credentials for 15,000 FortiGate devices (source)
- Hackers Hide Malware in Images to Deploy VIP Keylogger and 0bj3ctivity Stealer (source)
- IPany VPN breached in supply-chain attack to push custom malware (source)
- Stealthy 'Magic Packet' malware targets Juniper VPN gateways (source)
- Hacker infects 18,000 "script kiddies" with fake malware builder (source)
- North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS (source)
- How hackers target your Active Directory with breached VPN passwords (source)
- Hackers exploit SimpleHelp RMM flaws to deploy Sliver malware (source)
- SonicWall firewall exploit lets hackers hijack VPN sessions, patch now (source)