Click Studios revokes digital cert used by 'Follina' dropped malware

By
Follow google news

Does not know how credential was obtained.

Enterprise password management developer Click Studios has revoked the digital certificate used to sign the malware involved in the recent and actively exploited zero-day vulnerability, Follina, for MIcrosoft Office.

Click Studios revokes digital cert used by 'Follina' dropped malware

An unnamed anti-virus vendor contacted the Adelaide-based company to advise it that some copies of malware delivered through Follina were signed by Click Studios' DigiCert SHA 256 certificate.

Since digital certificates are used to ensure the integrity of code, Click Studios asked DigiCert to revoke the credential, which is normally used sign its password management software Passwordstate.

"While no Passwordstate code or functionality has been directly targeted or affected we have requested DigiCert to revoke the certificate. 

"Once revoked your Passwordstate instances availability may be impacted through operating system, antivirus, or endpoint protection software," Click Studios said [pdf]."

Click Studios does not know how its certificate was obtained by attackers, but said it cannot allow the credential to be used to digitally sign malware.

A new certificate to sign Click Studios' software has been obtained, and the company has recompiled Passwordstate to include the updated credential.

Follina abuses the remote template feature in the Microsoft Office protocol to execute code remotely with the MSDT diagnostics tool, bypassing detection by the Defender anti-malware utility.

 

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Hackers using F5 devices to target US gov networks

Hackers using F5 devices to target US gov networks

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

Austrade to replace its data centre core network

Austrade to replace its data centre core network

Log In

  |  Forgot your password?