Operation SignSight: trojanised Vietnam Government Certification Authority signing toolkit (2020)
What happened
ESET researchers Ignacio Sanmillan and Matthieu Faou reported on 17 December 2020 that the website of the Vietnam Government Certification Authority, ca.gov.vn, had been compromised from at least 23 July to 16 August 2020. During that window two installers for the authority's GCA01 digital-signature toolkit, gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi, were replaced with trojanised versions. Users had to download and run the installers themselves from the official site. The trojanised packages installed the legitimate application alongside a backdoor ESET named PhantomNet, delivered as Smanager_ssl.DLL, which uses certificate pinning to resist interception and supports plugin-delivered capability including lateral movement against machines of particular interest. Victims were identified in Vietnamese government and state agencies and in the Philippines.
In this corpus because SPARTA cites it against IA-0001.02 and because of what the compromised party was. A national certification authority is trust infrastructure: its signing toolkit is what other organisations use to establish that a document or a piece of software is what it claims to be, so compromising the distribution of that toolkit attacks the mechanism by which downstream signature checks mean anything. No space-sector victim is named by the source and none is asserted. The record's contribution is the contrast with the SolarWinds entry in the same batch, which maps the same technique in a different shape: SolarWinds was injection at build time with automatic delivery to up to 18,000 recipients and valid signatures, while SignSight was substitution at the download edge with manual installation and a narrow victim set, and the compromised party was itself a signing authority. IA-0001.02's description covers both, naming source alteration before build and binary swapping at distribution edges; carrying both records is what makes the technique legible rather than a label.
Attack vector
Compromise of a national certification authority's official website and replacement of two named signing-toolkit installers with trojanised versions, executed manually by users who trusted the distribution point.
Operational impact
Backdoor deployment at victims in Vietnam, where ESET says the VGCA signing toolkit appears to be deployed in Party and State agencies, and at victims in the Philippines, for whom ESET did not uncover the delivery mechanism. Lateral movement is a capability ESET suggests one plugin found on VirusTotal might provide rather than an observed act, and for the Vietnam attack ESET states it could not recover data about post-compromise activity or gain visibility into the attackers' end goal. No quantified victim count and no space-sector victim is named.
Affected segments
supply_chain
Disclosed
2020-12-17
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
IA-0001.02's description names swapping signed binaries at distribution edges among its methods. ESET establishes that two named installers on the certification authority's official site were replaced with trojanised versions during a dated window, and that users obtained them from that site. The behaviour is described rather than inferred, and this is the technique SPARTA's own bibliography cites against the operation.
Victims were compromised by trusting the certification authority's own distribution point, which is the trusted-relationship structure IA-0009.02 describes. The edge is derived rather than direct because ESET does not frame the compromise in those terms and because a certification authority is a trust provider rather than a vendor in the technique's usual sense of an integrator holding operational access. It is recorded because that trust relationship, not the malware, is what distinguishes this episode from an ordinary website compromise.
PhantomNet is a backdoor delivered by the trojanised installer and installed alongside the legitimate application so as not to draw attention, supporting plugin-delivered capability on command and using certificate pinning to resist interception. That is PER-0002.02's definition of a code path inserted to provide privileged functionality on cue, and ESET uses the word backdoor for it.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Mapped in the SolarWinds record and correctly absent here. Nothing was done to a build toolchain: the legitimate installers were built normally and replaced afterwards at the download edge.
The backdoor's purpose includes collection and ESET describes lateral movement to machines of interest, but no source used here documents what, if anything, was taken.
Software only.
No ground system is involved. Listed because "third-party infrastructure was compromised" invites it.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Operation SignSight: Supply-chain attack against a certification authority in Southeast AsiaVendor threat intelligence
Tier 1: First-party vendor research with named authors, named artefacts, a dated compromise window and a described malware family. The only public analysis of the episode.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.