Uploaded August 2025 | Updated September 2026, 5 hours ago
Yuta Sawabe (NTT Security Holdings, JP), Rintaro Koike (NTT Security Holdings, JP)
Yuta Sawabe is a SOC analyst at NTT Security Holdings, where he is primarily involved in log analysis and malware analysis. He previously worked on malicious domain names. His is an Information Processing Society of Japan JIP Special Paper Winner (2019). He has spoken at Botconf, HITCON, JSAC and CODE BLUE in the past.
Rintaro Koike is a security analyst at NTT Security Holdings. He is engaged in threat research and malware analysis. In addition, he is the founder of "nao_sec" and is in charge of threat research. He focuses on APT attacks targeting East Asia and web-based attacks. He has been a speaker at VB, SAS, Botconf, AVAR and others.
--
It is not uncommon for malware and malicious files to carry code signatures, which have become a traded commodity in cybercrime forums. This presentation begins with an overview of the current state of malicious code-signing certificates, including an examination of how these certificates are bought and sold in such forums.Our research uncovered unusual behaviours among sellers dealing in malicious code-signing certificates. By exploiting these behaviours, we successfully predicted the potential misuse of certain code-signing certificates several months in advance. This presentation will detail our methodology, the findings of our analysis, and propose practical measures to combat these sellers.Through this presentation, attendees will gain a comprehensive understanding of the current landscape of malicious code-signing certificates, experimental approaches to address the issue, and effective defence strategies. This knowledge will enable SOC, IR, CSIRT, and other cybersecurity professionals to take proactive measures against malware and malicious files bearing fraudulent code signatures.
Yuta Sawabe (NTT Security Holdings, JP), Rintaro Koike (NTT Security Holdings, JP)
Yuta Sawabe is a SOC analyst at NTT Security Holdings, where he is primarily involved in log analysis and malware analysis. He previously worked on malicious domain names. His is an Information Processing Society of Japan JIP Special Paper Winner (2019). He has spoken at Botconf, HITCON, JSAC and CODE BLUE in the past.
Rintaro Koike is a security analyst at NTT Security Holdings. He is engaged in threat research and malware analysis. In addition, he is the founder of "nao_sec" and is in charge of threat research. He focuses on APT attacks targeting East Asia and web-based attacks. He has been a speaker at VB, SAS, Botconf, AVAR and others.
--
It is not uncommon for malware and malicious files to carry code signatures, which have become a traded commodity in cybercrime forums. This presentation begins with an overview of the current state of malicious code-signing certificates, including an examination of how these certificates are bought and sold in such forums.Our research uncovered unusual behaviours among sellers dealing in malicious code-signing certificates. By exploiting these behaviours, we successfully predicted the potential misuse of certain code-signing certificates several months in advance. This presentation will detail our methodology, the findings of our analysis, and propose practical measures to combat these sellers.Through this presentation, attendees will gain a comprehensive understanding of the current landscape of malicious code-signing certificates, experimental approaches to address the issue, and effective defence strategies. This knowledge will enable SOC, IR, CSIRT, and other cybersecurity professionals to take proactive measures against malware and malicious files bearing fraudulent code signatures.










