Click Studios revokes digital cert used by 'Follina' dropped malware

By
Follow google news

Does not know how credential was obtained.

Enterprise password management developer Click Studios has revoked the digital certificate used to sign the malware involved in the recent and actively exploited zero-day vulnerability, Follina, for MIcrosoft Office.

Click Studios revokes digital cert used by 'Follina' dropped malware

An unnamed anti-virus vendor contacted the Adelaide-based company to advise it that some copies of malware delivered through Follina were signed by Click Studios' DigiCert SHA 256 certificate.

Since digital certificates are used to ensure the integrity of code, Click Studios asked DigiCert to revoke the credential, which is normally used sign its password management software Passwordstate.

"While no Passwordstate code or functionality has been directly targeted or affected we have requested DigiCert to revoke the certificate. 

"Once revoked your Passwordstate instances availability may be impacted through operating system, antivirus, or endpoint protection software," Click Studios said [pdf]."

Click Studios does not know how its certificate was obtained by attackers, but said it cannot allow the credential to be used to digitally sign malware.

A new certificate to sign Click Studios' software has been obtained, and the company has recompiled Passwordstate to include the updated credential.

Follina abuses the remote template feature in the Microsoft Office protocol to execute code remotely with the MSDT diagnostics tool, bypassing detection by the Defender anti-malware utility.

 

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Tasmanian gov agencies impacted by cyber attack

Tasmanian gov agencies impacted by cyber attack

Australian chief at US defence contractor L3Harris sold exploits to Russia

Australian chief at US defence contractor L3Harris sold exploits to Russia

Vic gov agencies flying blind on server security, audit finds

Vic gov agencies flying blind on server security, audit finds

Home Affairs streamlines risk vetting for gov tech suppliers

Home Affairs streamlines risk vetting for gov tech suppliers

Log In

  |  Forgot your password?