1200KM / simulation
T1553.002 Code Signing — Attack Simulation
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature. Code signing to verify software on first…
Technique description
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature. Code signing to verify software on first…
No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Darkhotel · G0012
- Molerats · G0021
- Lazarus Group · G0032
- FIN6 · G0037
- Suckfly · G0039
- Patchwork · G0040
- Winnti Group · G0044
- menuPass · G0045
- FIN7 · G0046
- OilRig · G0049
- CopyKittens · G0052
- PROMETHIUM · G0056
- Leviathan · G0065
- Silence · G0091
- TA505 · G0092
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Mustang Panda · G0129
- Moses Staff · G1009
- LuminousMoth · G1014
- Scattered Spider · G1015
- Saint Bear · G1031
- Daggerfly · G1034
- Medusa Group · G1051
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.