Weaponised malware: how criminals use digital certificates to cripple your organisation

Jeff Hudson · Network Security · 2011

The recent cyber-attack on an Iranian nuclear facility using the Stuxnet virus should worry all of us – not just those in close proximity who were in danger of being blown into the next world by the actions of a computer virus. The recent cyber-attack on an Iranian nuclear facility using the Stuxnet virus should worry all of us. The malware utilised multiple zero-day vulnerabilities and employed a signed digital certificate to authenticate itself. And its purpose was to cause physical damage – the first example of ‘weaponised’ malware. This should be a concern to all organisations. Most do not know how many certificates they have, where they are installed, who installed them, their validity and the expiration date. Jeff Hudson of Venafi explores the implications of weaponised malware, and what we can do about it.

Read the paper · More papers on PaperTik