Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1553/T1553.002
MITRE ATT&CK Sub-Technique

T1553.002: Code Signing

ShareXLinkedInRedditHN

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. (Citation: Wikipedia Code Signing) The certificates used during an operation may be created, acquired, or stolen by the adversary. (Citation: Securelist Digital Certificates) (Citation: Symantec Digital Certificates) Unlike [Invalid Code Signature](https://attack.mitre.org/techniques/T1036/001), this activity will result in a valid signature. Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform. (Citation: Wikipedia Code Signing)(Citation: EclecticLightChecksonEXECodeSigning) Code signing certificates may be used to bypass security policies that require signed code to execute on a system.

Tactics
Defense Impairment
Platforms
macOS, Windows

▪Parent technique

T1553: Subvert Trust Controls

▪Used by groups (27)

G0012DarkhotelG0021MoleratsG0032Lazarus GroupG0037FIN6G0039SuckflyG0040PatchworkG0044Winnti GroupG0045menuPassG0046FIN7G0049OilRigG0052CopyKittensG0056PROMETHIUMG0065LeviathanG0091SilenceG0092TA505G0093GALLIUMG0094KimsukyG0096APT41G0102Wizard SpiderG0129Mustang PandaG1009Moses StaffG1014LuminousMothG1015Scattered SpiderG1031Saint BearG1034DaggerflyG1051Medusa GroupG1054MirrorFace

▪Software using this technique (53)

S0091EpicmalwareS0144ChChesmalwareS0148RTMmalwareS0154Cobalt StrikemalwareS0163JanicabmalwareS0168GazermalwareS0170HelminthmalwareS0187DaserfmalwareS0210NerexmalwareS0234BandookmalwareS0262QuasarRATtoolS0266TrickBotmalwareS0284More_eggsmalwareS0342GreyEnergymalwareS0372LockerGogamalwareS0377EburymalwareS0415BOOSTWRITEmalwareS0455MetamorfomalwareS0475BackConfigmalwareS0491StrongPitymalwareS0501PipeMonmalwareS0504AnchormalwareS0520BLINDINGCANmalwareS0527CSPY DownloadertoolS0534BazarmalwareS0559SUNBURSTmalwareS0584AppleJeusmalwareS0603StuxnetmalwareS0611ClopmalwareS0624EcipekacmalwareS0646SpicyOmelettemalwareS0650QakBotmalwareS0663SysUpdatemalwareS0697HermeticWipermalwareS0698HermeticWizardmalwareS1016MacMamalwareS1070Black BastamalwareS1149CHIMNEYSWEEPmalwareS1150ROADSWEEPmalwareS1151ZeroClearemalwareS1183StrelaStealermalwareS1196Troll StealermalwareS1197GoBearmalwareS1213Lumma StealermalwareS1226BOOKWORMmalwareS1228PUBLOADmalwareS1232SplatDroppermalwareS1233PAKLOGmalwareS1235CorKLOGmalwareS1238STATICPLUGINmalwareS1239TONESHELLmalwareS1240RedLine StealermalwareS9024SPAWNCHIMERAmalware

▪Reference

T1553.002on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.