Umbra Wiki attack-pattern attack-pattern/CAPEC-473
Back to wiki

CAPEC-473 — Signature Spoof

provenance: imported · ATT&CK: T1036.001 T1553.002 · CWE: CWE-20 CWE-290 CWE-327

CAPEC-473: Signature Spoof

MITRE CAPEC attack pattern

Status Draft
Typical severity
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

An attacker generates a message or datablock that causes the recipient to believe that the message or datablock was generated and cryptographically signed by an authoritative or reputable source, misleading a victim or victim operating system into performing malicious actions.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-20, CWE-290, CWE-327

ATT&CK techniques: T1036.001, T1553.002

Prerequisites

  • The victim or victim system is dependent upon a cryptographic signature-based verification system for validation of one or more security events or actions.
  • The validation can be bypassed via an attacker-provided signature that makes it appear that the legitimate authoritative or reputable source provided the signature.

Skills required

  • High: Technical understanding of how signature verification algorithms work with data and applications

Consequences

  • Access Control, Authentication: Gain Privileges

Source