Fabricated Certificate Masquerade
Malware authors generate self-signed code-signing certificates with Subject/Issuer Common Names borrowed from legitimate open-source or commercial software projects. Unlike stolen-certificate-signing, these certificates are freshly generated by the attacker; they are not stolen from a compromised CA or organization. The goal is to make a binary appear signed during superficial triage, improving social-engineering execution rates even though the certificate will fail strict Authenticode validation.
Pattern
- Certificate is self-signed (issuer == subject) or issued by an untrusted private CA
- Subject CN belongs to a real, recognizable open-source project (e.g.
Equalizer APO,PuTTY,FileZilla) - Validity window is often post-dated to the malware compile time (years later), indicating fresh generation at build time
- A timestamp counter-signature from a real CA (e.g. Sectigo, DigiCert) may be present; this only proves when signing occurred and does not make the cert trusted
- The certificate chain will fail validation on any host that enforces TrustedPublisher / Code Integrity policies
Distinction from Stolen Certificates
| Feature | Fabricated | Stolen |
|---|---|---|
| Issuer | Self-signed or private CA | Legitimate public CA (DigiCert, Sectigo, Amazon, etc.) |
| Subject CN | Real open-source project name | Real organization/domain name |
| Chain validation | Fails everywhere | Passes until revoked |
| Serial entropy | Often low / repeated across samples | Normal CA serial distribution |
| Timestamp | Frequently post-dated by years | Aligned with legitimate issuance window |
Observed In
- unattributed sample
616740a4— Themida-packed PE masquerading as Proton Drive, self-signed CN=Equalizer APO, Sectigo timestamp counter-signature ^[/intel/analyses/616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd.html] - unattributed sample
01372355— Themida-packed PE masquerading as TreeSize Disk Space Manager, self-signed CN=Logitech, Sectigo timestamp counter-signature,dropped-by-gcleaner/mix8.filedistribution ^[/intel/analyses/013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7.html] - d52f85 sample
78434b53— Themida-packed PE masquerading as Ubisoft Connect, self-signed CN=Lightshot, DigiCert Trusted G4 timestamp counter-signature ^[/intel/analyses/78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd.html] - unclassified-nsis-dropper — Fabricated self-signed certs with Danish/French word-salad metadata (27% unsigned rate in cluster). Sibling
600d4f1cuses non-standard SHA-384 digest, causing standard Authenticode tools to choke. - 54e64e — Fabricated
godaddy.com/WE1Authenticode
Detection
- Compare certificate Subject CN against the file's version-info, filename, and behavioral profile. A mismatch (e.g. audio equalizer cert on a cloud-storage executable) is a strong signal.
- Check certificate validity start date against PE compile timestamp. A 6+ year gap (compile 2020, cert valid 2026) suggests fabrication.
- Verify chain with
signtool verify /paor OpenSSLpkcs7 -print_certs. Self-signed certs fail immediately. - Hunt for repeated Subject CNs across unrelated malware families — a single attacker re-using the same self-signed CN is a cluster fingerprint.
Related
- stolen-certificate-signing — the legitimate-CA variant
- version-info-masquerade — often paired with fabricated certs
- legitimate-library-masquerade — same philosophy applied to metadata rather than certificates