Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-474 — Signature Spoofing by Key Theft
CAPEC-474

Signature Spoofing by Key Theft

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.

Mitigation

Restrict access to private keys from non-supervisory accounts | Restrict access to administrative personnel and processes only | Ensure all remote methods are secured | Ensure all services are patched and up to date

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.