Blog | G5 Cyber Security

BlackTech APT using stolen D-Link certificates to spread malware

A cyber-espionage group tracked as BlackTech is abusing code-signing certificates stolen from D-Link for distribution of their malware. The attackers used the certificates to sign the code of the Plead backdoor that has been in the wild since at least 2012. Most of the cyber espionage group’s victims are in the East Asia region, particularly Taiwan, Japan, and Hong Kong. ESET identified two different malware families that were abusing the stolen certificate. The two affected certificates were revoked, effective July 3rd, 2018.”]

Source: https://securityaffairs.co/wordpress/74317/malware/blacktech-apt-stolen-certificates.html

Exit mobile version