StandardDraft
CAPEC-473Signature Spoof
Abstraction
Standard
Status
Draft
Description
An attacker generates a message or datablock that causes the recipient to believe that the message or datablock was generated and cryptographically signed by an authoritative or reputable source, misleading a victim or victim operating system into performing malicious actions.
Metadata: standard CAPEC pattern, status draft. Underlying weaknesses: CWE-20, CWE-327, CWE-290. Mapped ATT&CK techniques: [object Object], [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 3
MITRE ATT&CK crosswalk· 2
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass by Spoofingcwe-290 | 100% | live |
| Weakness | Use of a Broken or Risky Cryptographic Algorithmcwe-327 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
Related to2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Code Signingt1553.002 | 100% | live |
| SubTechnique | Invalid Code Signaturet1036.001 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.