# T1588.003 Code Signing Certificates

> As of 2026-10-05, T1588.003 (Code Signing Certificates) appears in 21 tracked threats, first reported 2026-02-27 and most recently 2026-09-15, with linked actors including MuddyWater, UNC1549, APT43; it most often appears alongside T1553.002 (Code Signing).

- **Tracked threats:** 21 (3 critical, 18 high)
- **First seen:** 2026-02-27
- **Last seen:** 2026-09-15
- **Threat actors:** 9
- **Detection rules:** 10 (counts only; Blue tier and above)

## Key facts

- **ID:** T1588.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1588
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1588/003/

## Activity timeline

T1588.003 first appeared in tracked threats on 2026-02-27 and was most recently reported on 2026-09-15. The busiest month was 2026-07 with 8 reports, and 21 of the 21 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1588.003 Code Signing Certificates is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588). Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 3 critical, 18 high.

Threats that use T1588.003 most often also use [T1553.002 Code Signing](https://intel.threadlinqs.com/technique/T1553.002) (20 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (19 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (19 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (18 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1588.003; the most frequent are [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (2), [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) (2), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) (1), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1588.003.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1588.003, per MITRE ATT&CK.

- Malware Repository — Malware Metadata

## Threat actors using it

- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 1
- [REvil](https://intel.threadlinqs.com/actor/REvil) — 1
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 1
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 1

## Tracked threats

21 tracked threats use T1588.003.

- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…](https://intel.threadlinqs.com/threat/TL-2026-2527) — high — 2026-09-15
- [D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…](https://intel.threadlinqs.com/threat/TL-2026-2147) — high — 2026-08-25
- [Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…](https://intel.threadlinqs.com/threat/TL-2026-1649) — critical — 2026-07-23
- [Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…](https://intel.threadlinqs.com/threat/TL-2026-1643) — high — 2026-07-22
- [GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…](https://intel.threadlinqs.com/threat/TL-2026-1579) — critical — 2026-07-20
- [CrashStealer: Notarized Fake Apple CrashReporter App Steals macOS Keychain, Browser, and Crypto Wallet…](https://intel.threadlinqs.com/threat/TL-2026-1358) — high — 2026-07-15
- [AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver…](https://intel.threadlinqs.com/threat/TL-2026-1344) — high — 2026-07-15
- [11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1340) — high — 2026-07-14
- [JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…](https://intel.threadlinqs.com/threat/TL-2026-1142) — high — 2026-07-06
- [Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting](https://intel.threadlinqs.com/threat/TL-2026-1126) — high — 2026-07-01
- [The BYOVD Epidemic: Attackers Weaponize Trusted Windows Drivers to Kill Security Software](https://intel.threadlinqs.com/threat/TL-2026-2297) — high — 2026-06-30
- [Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers](https://intel.threadlinqs.com/threat/TL-2026-0822) — high — 2026-06-16
- [DinDoor Deno-Based RAT — Fake AI/Audio Software on GitHub & SourceForge (ChatGPT/Claude/AutoTune/Kontakt)…](https://intel.threadlinqs.com/threat/TL-2026-0590) — high — 2026-05-26
- [Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…](https://intel.threadlinqs.com/threat/TL-2026-0581) — high — 2026-05-25
- [Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via…](https://intel.threadlinqs.com/threat/TL-2026-0562) — high — 2026-05-22
- [Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace\[.\]cloud Operation…](https://intel.threadlinqs.com/threat/TL-2026-0533) — high — 2026-05-19
- [Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and…](https://intel.threadlinqs.com/threat/TL-2026-0500) — high — 2026-05-12
- [JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…](https://intel.threadlinqs.com/threat/TL-2026-0490) — high — 2026-05-09
- [DAEMON Tools Lite Supply-Chain Compromise — Trojanized Signed Installers Deploy Multi-Stage Infostealer +…](https://intel.threadlinqs.com/threat/TL-2026-0472) — critical — 2026-05-07
- [Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0218) — high — 2026-03-12
- [PlugX Meeting Invitation Campaign — China-Nexus MSBuild LOLBIN + GDATA DLL Sideloading, RC4 Encrypted C2…](https://intel.threadlinqs.com/threat/TL-2026-0153) — high — 2026-02-27

## Related CVEs

CVEs referenced by the tracked threats that use T1588.003, most frequent first.

- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)

## Detection coverage

Threadlinqs maintains 10 detection rules mapped to T1588.003 (SPL 3, KQL 3, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

10 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588) — 363 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1588.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
