Malware authors behind Duqu 2.0 used a stolen certificate from the Foxconn company to implement a persistence mechanism and stay stealthy. The threat actors used valid certificate from Hon Hai Precision Industry Co. LTD (aka Foxconn Technology Group) to digitally sign the source code of a driver designed to mask command-and-control traffic. Foxconn provides electronic components for a wide number of companies, including Apple and BlackBerry. The majority of Duqu infections was observed between 2014 and 2015 concurrently to the negotiations on the Iranian nuclear program.”]
Source: https://securityaffairs.co/wordpress/37826/malware/duqu-2-0-stolen-certificate.html

