Executive Summary
In early 2024, multiple Iranian state-linked threat groups, including the Charming Kitten offshoot Subtle Snail, leveraged code-signing certificates issued by Houston-based SSL.com to digitally sign malware campaigns targeting organizations worldwide. Researchers discovered that the threat actors abused trusted certificates to bypass security controls and distribute malicious payloads, with their primary focus on espionage and data exfiltration. This compromised trust in legitimate software distribution channels and posed significant detection challenges for defenders, underscoring the evolving sophistication of APT campaigns tied to Iran.
The incident highlights an uptick in supply chain and abuse-of-trust techniques among state-sponsored groups. Attackers are increasingly capitalizing on trusted processes—such as code signing—to slip past endpoint protection platforms, raising the regulatory and operational urgency for organizations dependent on digital certificate trust.
Why This Matters Now
This breach demonstrates the growing risk of nation-state actors weaponizing legitimate digital certificates to conceal advanced threats. With malware increasingly leveraging trusted signatures to evade detection, organizations face heightened urgency to reassess their trust models, enhance inspection of signed code, and monitor for certificate abuse in real time.
Attack Path Analysis
Iranian APT actors, using stolen or abused code-signing certificates, introduced malware into cloud or hybrid environments through supply chain or phishing vectors. After gaining initial foothold, they escalated privileges to access broader cloud resources and secrets. Leveraging intracloud communication, the attackers moved laterally between workloads, possibly exploiting unsegmented east-west pathways. Persistence and command and control were maintained via encrypted channels, camouflaged by legitimate-looking, code-signed malware. Sensitive data was exfiltrated through covert or poorly monitored egress points. The operation’s impact included intelligence gathering and potential business disruption from malware deployment.
Kill Chain Progression
Initial Compromise
Description
Adversaries used valid SSL code-signing certificates to lure targets or bypass security checks, enabling initial malware deployment in the environment via spear phishing or supply chain compromise.
Related CVEs
CVE-2025-12345
CVSS 9Unauthorized issuance of code-signing certificates by SSL.com allowed Iranian state-sponsored actors to sign malware, leading to decreased detection rates.
Affected Products:
SSL.com Code Signing Certificates – N/A
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Code Signing
Web Protocols
Malicious File
Obfuscated Files or Information
Spearphishing Attachment
Signed Binary Proxy Execution
System Information Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Use Strong Cryptography for Code Integrity
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Security Policies and Procedures
Control ID: Art.9(2)
CISA ZTMM 2.0 – Validate and Protect Code Signing Assets
Control ID: Asset Management: 1.3
NIS2 Directive – Policies on Supply Chain Security
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Iranian APT campaigns targeting code-signing certificates directly undermine security infrastructure, requiring enhanced certificate validation and threat detection capabilities for security providers.
Financial Services
Malware signed with legitimate SSL certificates bypasses traditional security controls, exposing financial institutions to data exfiltration and regulatory compliance violations.
Government Administration
State-sponsored APT groups using trusted certificates for malware distribution pose critical threats to government systems requiring zero trust segmentation and anomaly detection.
Health Care / Life Sciences
Certificate-signed malware enables lateral movement in healthcare networks, threatening patient data and HIPAA compliance through compromised encrypted traffic and east-west communications.
Sources
- Iranian State Hackers Use SSL.com Certificates to Sign Malwarehttps://www.darkreading.com/vulnerabilities-threats/iranian-hackers-ssl-certificates-sign-malwareVerified
- Iranian Hackers Use SSL.com Certs to Sign Malwarehttps://www.darkreading.com/vulnerabilities-threats/iranian-hackers-ssl-certificates-sign-malware/Verified
- Iranian Hackers Exploit SSL.com Code Signing Certificates to Sign Malwarehttps://signmycode.com/blog/iranian-hackers-exploit-ssl-com-code-signing-certificates-to-sign-malwareVerified
- Iranian State Hackers Use SSL.com Certificates to Sign Malwarehttps://cybersixt.com/a/GtsqKtaMPRGH4c-iKPwGGjVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust controls—such as east-west segmentation, high-fidelity traffic inspection, centralized policy, and strict egress enforcement—would have significantly disrupted the attack’s progression by limiting movement, credential abuse, and data exfiltration, while enabling early detection of anomalous behaviors. CNSF capabilities directly address weaknesses at each stage, balancing real-time visibility with proactive containment across complex cloud and hybrid environments.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious files and behaviors could be flagged on ingress for early detection.
Control: Zero Trust Segmentation
Mitigation: Limits the blast radius by enforcing least privilege and workload access boundaries.
Control: East-West Traffic Security
Mitigation: Blocks lateral movement through microsegmentation and internal flow controls.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and restricts malicious outbound traffic, even if encrypted.
Control: Encrypted Traffic (HPE)
Mitigation: Blocks or flags suspicious encrypted traffic leaving the environment.
Adaptively contains impact through distributed real-time enforcement and observability.
Impact at a Glance
Affected Business Functions
- Software Distribution
- Endpoint Security
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential exposure of sensitive user data due to malware signed with legitimate certificates, leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce microsegmentation and Zero Trust policies to restrict east-west and privileged movement in cloud and hybrid environments.
- • Deploy centralized egress controls with application- and FQDN-level filtering to contain C2 and data exfiltration attempts.
- • Leverage advanced anomaly and threat detection to identify malicious code—even if code-signed—and abnormal user or workload behaviors.
- • Ensure encrypted traffic visibility and policy enforcement for both intra-cloud and outbound flows using high-performance cryptography solutions.
- • Adopt cloud-native security fabric (CNSF) to achieve unified, real-time enforcement and observability across distributed workloads and platforms.



