Ransomware gang Lapsus$ is tricking users into installing malware by disguising it as verified and signed certificates. This comes after the Laspsus$ group leaked confidential data belonging to chipmaker Nvidia and South Korean manufacturer Samsung. Malware could be written to specifically attack a particular organization to gather information and then act as a command-and-control server, says Andrew Whaley, senior technical director at Promon, a Norwegian application security company. To exploit this process, attackers disguise files as legitimate and bypass security, allowing malware to be uploaded to Windows.”]
Source: https://www.cuinfosecurity.com/how-lapsus-uses-stolen-source-code-to-disguise-malware-a-18684

