January 11, 2016 By Larry Loeb 2 min read

Researchers at security company Zscaler have found malware that uses compromised digital certificates to evade detection. Dubbed Spymel, it uses a .NET executable signed with a legitimate DigiCert-issued certificate. The malware allows malicious actors to steal information from compromised machines and spy on victims.

How Spymel Abuses Digital Certificates

Spymel is a Trojan that starts with JavaScript that is not obfuscated. This malware typically will show up via a spammed email. The executable, which is obfuscated, gets downloaded from a location hard-coded in the JavaScript.

“[The] .NET binary … is digitally signed with a certificate issued to SBO INVEST,” Zscaler researchers noted. “The certificate was promptly revoked by DigiCert when notified and, therefore, is not active in any attack. We noticed a newer variant arose within two weeks of the first variant, using another certificate issued to SBO INVEST that is also revoked.”

The configuration data, including command-and-control (C&C) servers as well as file and registry information, is hard-coded within the executable. The C&C server is hosted on the android.sh domain, which has a German IP address. The malware communicates via port 1216.

SecurityWeek reported that Spymel is designed to work on both Windows XP and Windows 7 systems.

Many Functions, All Invasive

There are several modules to Spymel. One is a keylogger, which is a module that logs all user keystrokes into a log file at %Application Data%\ProgramFiles(32.1)\svchost.exe.tmp.

Zscaler found that the C&C server may send a host of commands to infected machines. These include collecting information about the infected system and the files found on it, as well as deleting, executing or renaming a specified file. A specified file can be uploaded to the C&C and so can a screenshot of the desktop. Enabling or disabling video recording can also be performed.

A ProtectMe module allows Spymel to prevent the user from terminating the malware or run other processes. Tools such as TaskMgr, Procexp, ProcessHacker and Taskkill are disabled by making the OK button on the confirmation prompt for Process Explorer not appear as a valid choice. It does this by using the GetForegroundWindow() API to get a handle of the active window and change how it works.

Abuse of digital certificates has been a technique used by malware in the past. SecurityWeek noted that more than 6,000 cases of malware using certs was recording in 2014 alone.

More from

Unpacking the NIST cybersecurity framework 2.0

4 min read - The NIST cybersecurity framework (CSF) helps organizations improve risk management using common language that focuses on business drivers to enhance cybersecurity.NIST CSF 1.0 was released in February 2014, and version 1.1 in April 2018. In February 2024, NIST released its newest CSF iteration: 2.0. The journey to CSF 2.0 began with a request for information (RFI) in February 2022. Over the next two years, NIST engaged the cybersecurity community through analysis, workshops, comments and draft revision to refine existing standards…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Obtaining security clearance: Hurdles and requirements

3 min read - As security moves closer to the top of the operational priority list for private and public organizations, needing to obtain a security clearance for jobs is more commonplace. Security clearance is a prerequisite for a wide range of roles, especially those related to national security and defense.Obtaining that clearance, however, is far from simple. The process often involves scrutinizing one’s background, financial history and even personal character. Let’s briefly explore some of the hurdles, expectations and requirements of obtaining a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today