It's been only a month since the Let's Encrypt Certificate Authority has launched a beta program for distributing free HTTPS certificates to the public, and hackers have begun to abuse the malware distribution service through seemingly secure websites.
In December, security firm Trend Micro spotted some users in Japan infected with a malicious server that hosted the Angler Exploit Kit. Trojans allowed hackers to gain remote access to infected systems without their owners knowing it.
The company reports that malvertisers have used a technique called domain shadowing, with which they can gain access to a trusted domain (such as a bank's main site). This can lead users to their own server, which masks the password-aborting activity.
To make the cheating attempt more believable, they use a subdomain that is protected by the Let's Encrypt (HTTPS) free security certificate.
In the case of the Trend Micro survey, the attackers hosted a malicious ad that seemed to be related to a legitimate domain.
The company says this was possible because Let's Encrypt before issuing new certificates checks the domains from the Google safe browsing API. This of course does not stop invaders to acquire a new certificate and create subdomains with malware under the protection of a legitimate domain.
According to the Trend Micro report, the incident highlights the possible issues of Let's Encrypt and calls on the company to be ready to cancel abusive certificates.
Dimitris hates Mondays...

