top of page

Tracking DigiCert Hack - IP Address Source, Purpose & Destination of Stolen Data

  • May 4
  • 2 min read


Websites, apps, and related online platforms require security certification to ensure consumers can verify their legitimacy. It’s also required for online communications and transactions to ensure each party is a legitimate actor. SSL/TLS certificates, third-party trust seals, and app store verification are some measures used to ensure secure and legitimate transactions.

 

But what happens if the company issuing security certificates has been compromised?

 

DigiCert Hacking and Its Implications

 

Cyber Security News reported a hack against DigiCert in their effort to distribute Zhong Stealer malware. The hack was done through a compromised .zip file containing a .scr executable. Hackers uploaded the ZIP file through the company’s support team and succeeded on their fifth attempt.

 

The hackers used the following IP addresses during the attack:

 

●    82.23.186.8

●    154.12.185.32

●    45.144.227.12

●    203.160.68.2

●    154.12.185.30

●    62.197.153.45

●    45.144.227.29

 

DigiCert is a security company that specializes in issuing TLS/SSL Certificates and other related security services. The company issues certificates to businesses and companies for faster transactions. According to their official website, “DigiCert is a global leader in Intelligent Trust. We protect the digital world by ensuring the security, privacy, and authenticity of every interaction.”

 

The purpose of the hack is to retrieve relevant data and unused security certificates. The stolen information is used to make their Zhong Stealer malware appear legitimate.

 

Basically, their purpose in hacking is to retrieve data and certificates to make their malware look legitimate. Its goal is not just to steal important information, but to infiltrate its target and steal as much data as possible.

 

Successful Infiltration and Mitigation

 

DigiCert’s report on Mozilla indicated successful infiltration. However, they have identified 60 compromised certificates and revoked them. Aside from revoking these certificates, they have also reported that these certificates were actually used:

 

“27 of the revoked certificates were explicitly linked to the threat actor (11 were identified in certificate problem reports provided to DigiCert by community members linking the certificates to malware, and 16 were identified during our own investigation).”

 

Zhong Stealer Malware is not your common garden variety malware. It’s more than just IP address monitoring - it's malware designed for attacking fintech companies and other related services as well as cryptocurrencies. Any.Run’s Malware analysis reveals that their stolen data is stored on a C2 server in Hong Kong. It’s also a full-on infiltration because it can change Registry Keys to prevent detection.

 

A Challenge for IT Security Specialists

 

DigiCert infiltration and fintech vulnerability should be a warning sign for IT security specialists. Hackers are no longer focused on brute-force attacks on different institutions. Part of their infiltration plan now involves making their malware look legitimate to evade detection for as long as possible. Tracking incoming and outgoing communication is a must, and every suspected transaction should be addressed as soon as possible. Applications and websites should be checked carefully to ensure they are legitimate. IT security specialists should also stay informed about the latest malware attacks.

 
 
 

Recent Posts

See All

Comments


bottom of page