[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmyaRuhkTko6jNNt8jMvl64brBlCdE53etqYOhYk6WaY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"f91823d7-0abf-41db-8c60-001c9da265ee","apt-group-exploits-legitimate-code-signing-certificates-to-evade-detection","4a247e9a-c5f5-4360-855c-d3f463287874","APT Group Exploits Legitimate Code-Signing Certificates to Evade Detection","APT-Q-27 threat actors compromised or misused legitimate DigiCert code-signing certificates belonging to Brunner Informatik AG to sign their malware, allowing malicious code to appear trustworthy to security systems. This supply chain attack demonstrates how attackers can exploit the trust model of digital certificates to bypass security controls that rely on signature verification. The incident highlights critical vulnerabilities in certificate management and the need for enhanced monitoring of code-signing activities, as compromised certificates can enable widespread malware distribution while evading detection.","**Immediate actions:**\n- Audit all active code-signing certificates and revoke any potentially compromised credentials\n- Implement strict access controls and multi-factor authentication for certificate storage systems\n- Monitor certificate usage logs for unauthorized or suspicious signing activities\n\n**Long-term improvements:**\n- Establish certificate lifecycle management with regular rotation and renewal procedures\n- Implement hardware security modules (HSMs) to protect private keys used for code signing\n- Create incident response procedures specifically for certificate compromise scenarios\n\n**Detection measures:**\n- Deploy certificate transparency monitoring to detect unauthorized certificate issuance\n- Implement behavioral analysis to identify anomalous code-signing patterns\n- Establish threat intelligence feeds to monitor for misuse of organizational certificates",[12,13,14,15,16],"CIS Control 2","CIS Control 16","NIST SP 800-57","NIST SC-17","ISO 27001 A.14.1.3","published","2026-04-11T11:07:36.93533+00:00","2026-04-11T11:07:36.605+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2042906240901107988","and-it-was-only-2-days-ago-when-i-told-squiblydooblog-about-a-sample-from-this-a-4d2b87","And it was only 2 days ago when I told @SquiblydooBlog about a sample from this APT-Q-27 actors t...",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"167ed0ba-dad4-49b6-bca2-4b6eec766cd8","2026-04-11","afternoon","ThreatNoir Weekend Brief — April 11","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-11\u002Fthreatnoir-afternoon-brief-2026-04-11.mp3"]