Trusted Design

T1130 - Install Root Certificate

概要

Root certificates are used in public key cryptography to identify a root certificate authority (CA). When a root certificate is installed, the system or application will trust certificates in the root's chain of trust that have been signed by the root certificate. (Citation: Wikipedia Root Certificate) Certificates are commonly used for establishing secure TLS/SSL communications within a web browser. When a user attempts to browse a website that presents a certificate that is not trusted an error message will be displayed to warn the user of the security risk. Depending on the security settings, the browser may not allow the user to establish a connection to the website.

Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system. Adversaries have used this technique to avoid security warnings prompting users when compromised systems connect over HTTPS to adversary controlled web servers that spoof legitimate websites in order to collect login credentials. (Citation: Operation Emmental)

Atypical root certificates have also been pre-installed on systems by the manufacturer or in the software supply chain and were used in conjunction with malware/adware to provide a man-in-the-middle capability for intercepting information transmitted over secure TLS/SSL communications. (Citation: Kaspersky Superfish)

Root certificates (and their associated chains) can also be cloned and reinstalled. Cloned certificate chains will carry many of the same metadata characteristics of the source and can be used to sign malicious code that may then bypass signature validation tools (ex: Sysinternals, antivirus, etc.) used to block execution and/or uncover artifacts of Persistence. (Citation: SpectorOps Code Signing Dec 2017)

In macOS, the Ay MaMi malware uses /usr/bin/security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /path/to/malicious/cert to install a malicious certificate as a trusted root certificate into the system keychain. (Citation: objective-see ay mami 2018)

管理者によるコメント

MITRE ATT&CKにおいて、T1130は「Install Root Certificate(ルート証明書のインストール)」として定義されている「防御回避(Defense Evasion)」および「初期アクセス/認証情報盗取(Credential Access)」に関わるテクニックです。

攻撃者がターゲットのシステムや端末に自前で作成した「悪意あるCA(認証局)のルート証明書」を勝手に読み込ませて信頼させることで、SSL/TLS等の暗号化通信の盗聴(MiTM:中間者攻撃)や、不正なプログラム(署名付きマルウェア)の正常実行を可能にする手法です。

1. 概要(攻撃者は何を実現できるのか?)

この手法で攻撃者は、「システムの『証明書による信頼ルール』を根底から汚染し、セキュリティ機能を完全に無効化すること」を実現します。

2. 攻撃の流れ

Windowsの場合、システム標準のコマンドツール(certutil.exe 等)やレジストリ操作、またはグループポリシーの変更を悪用して信頼されたルート証明書ストア(Root ストア)に追加します。

  1. 初期侵入と権限昇格:
    フィッシングや脆弱性攻撃などを介してターゲット端末に侵入し、管理者権限(Administrator または SYSTEM)を獲得します。

  2. 悪意あるCA証明書の作成と配置:
    攻撃者は自前で作成した偽のルート証明書(例: malicious_ca.crt)をターゲット端末のローカル環境に書き込みます。

  3. 証明書のインストール(T1130の発動):
    管理者権限で以下のコマンド等を実行し、信頼されたルート証明機関ストアへ登録します。

    • コマンドの例(Windows certutil の悪用):
      certutil.exe -addstore -f "Root" C:\Windows\Temp\malicious_ca.crt

      • -addstore:証明書ストアへの追加を指定
      • "Root":信頼されたルート証明機関ストアを指定
    • PowerShellの例:
      Import-Certificate -FilePath "C:\Windows\Temp\malicious_ca.crt" -CertStoreLocation Cert:\LocalMachine\Root

  4. 中間者攻撃または署名検証回避の実行(目的達成):
    信頼された証明書として登録された後は、ローカルのプロキシ(AdwareやSpywareなど)を介して通信を盗聴したり、偽の署名付きマルウェアを警告なしで実行させたりします。

3. 防御・対策

ルート証明書ストアへの書き込み権限の管理と、証明書追加イベントの厳重なログ監視が必要です。

4. 重要ポイント

5. 関連する主なCWE

6. 関連する代表的なCVE

本手口は「管理者権限をとった後のOS標準機能の悪用(設定変更)」であることが多いため、個別のソフトウェア脆弱性(CVE)というよりは設計仕様を突くものですが、証明書ストアやコード署名検証をバイパスする脆弱性と密接に関連します。

実務上のアドバイス:
SOCやセキュリティアナリストのログ確認において、certutil.exe が -addstore 引数付きで動いているケースを見つけたら、即座に「どの証明書ファイル(.crt/.cer/.pfx)が指定されたか」を特定してください。

特に、そのコマンドの実行元プロセス(親プロセス)が powershell.exe、不審なバッチファイル(cmd.exe)、あるいは野良の .exe プロセス である場合、高確率で旧 T1130(現 T1553.004)による暗号化通信の盗聴準備または永続化攻撃が進行しています。対象端末を隔離し、Cert:\LocalMachine\Root の中身を即時監査することが推奨されます。

分析

この攻撃手法を利用する脅威アクター

関連する CVE

攻撃手法 – 脅威アクター Graph


← Technique一覧に戻る ← Tactics一覧に戻る