typeconceptconfidencehighcreated2026-08-01updated2026-08-24signingauthenticodemasqueradingcertificateevasion

Fabricated Certificate Masquerade

Malware authors generate self-signed code-signing certificates with Subject/Issuer Common Names borrowed from legitimate open-source or commercial software projects. Unlike stolen-certificate-signing, these certificates are freshly generated by the attacker; they are not stolen from a compromised CA or organization. The goal is to make a binary appear signed during superficial triage, improving social-engineering execution rates even though the certificate will fail strict Authenticode validation.

Pattern

  • Certificate is self-signed (issuer == subject) or issued by an untrusted private CA
  • Subject CN belongs to a real, recognizable open-source project (e.g. Equalizer APO, PuTTY, FileZilla)
  • Validity window is often post-dated to the malware compile time (years later), indicating fresh generation at build time
  • A timestamp counter-signature from a real CA (e.g. Sectigo, DigiCert) may be present; this only proves when signing occurred and does not make the cert trusted
  • The certificate chain will fail validation on any host that enforces TrustedPublisher / Code Integrity policies

Distinction from Stolen Certificates

Feature Fabricated Stolen
Issuer Self-signed or private CA Legitimate public CA (DigiCert, Sectigo, Amazon, etc.)
Subject CN Real open-source project name Real organization/domain name
Chain validation Fails everywhere Passes until revoked
Serial entropy Often low / repeated across samples Normal CA serial distribution
Timestamp Frequently post-dated by years Aligned with legitimate issuance window

Observed In

  • unattributed sample 616740a4 — Themida-packed PE masquerading as Proton Drive, self-signed CN=Equalizer APO, Sectigo timestamp counter-signature ^[/intel/analyses/616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd.html]
  • unattributed sample 01372355 — Themida-packed PE masquerading as TreeSize Disk Space Manager, self-signed CN=Logitech, Sectigo timestamp counter-signature, dropped-by-gcleaner / mix8.file distribution ^[/intel/analyses/013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7.html]
  • d52f85 sample 78434b53 — Themida-packed PE masquerading as Ubisoft Connect, self-signed CN=Lightshot, DigiCert Trusted G4 timestamp counter-signature ^[/intel/analyses/78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd.html]
  • unclassified-nsis-dropper — Fabricated self-signed certs with Danish/French word-salad metadata (27% unsigned rate in cluster). Sibling 600d4f1c uses non-standard SHA-384 digest, causing standard Authenticode tools to choke.
  • 54e64e — Fabricated godaddy.com/WE1 Authenticode

Detection

  1. Compare certificate Subject CN against the file's version-info, filename, and behavioral profile. A mismatch (e.g. audio equalizer cert on a cloud-storage executable) is a strong signal.
  2. Check certificate validity start date against PE compile timestamp. A 6+ year gap (compile 2020, cert valid 2026) suggests fabrication.
  3. Verify chain with signtool verify /pa or OpenSSL pkcs7 -print_certs. Self-signed certs fail immediately.
  4. Hunt for repeated Subject CNs across unrelated malware families — a single attacker re-using the same self-signed CN is a cluster fingerprint.

Related