MITRE ATT&CK Technique
T1553.002Code Signing
- First Reported
- Sep 22, 2026
- Latest Reported
- Sep 22, 2026
Official Description
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. (Citation: Wikipedia Code Signing) The certificates used during an operation may be created, acquired, or stolen by the adversary. (Citation: Securelist Digital Certificates) (Citation: Symantec Digital Certificates) Unlike [Invalid Code Signature](https://attack.mitre.org/techniques/T1036/001), this activity will result in a valid signature.
Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform. (Citation: Wikipedia Code Signing)(Citation: EclecticLightChecksonEXECodeSigning)
Code signing certificates may be used to bypass security policies that require signed code to execute on a system.
Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform. (Citation: Wikipedia Code Signing)(Citation: EclecticLightChecksonEXECodeSigning)
Code signing certificates may be used to bypass security policies that require signed code to execute on a system.
- Tactics
- Defense Impairment
- Platforms
- macOS, Windows
- Parent Technique
- T1553 · Subvert Trust Controls
- MITRE Version
- 2.0
- Last Modified
- May 12, 2026
Reported Context (1)
- The article reports use of a valid Adobe DigiCert signature on the loader to pass signature and reputation checks. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
MITRE ATT&CK (26)
Vendors (8)
Products (10)
Tools (3)
Industries (6)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.