CAPEC™ 473: Signature Spoof
Description
An attacker generates a message or datablock that causes the recipient to believe that the message or datablock was generated and cryptographically signed by an authoritative or reputable source, misleading a victim or victim operating system into performing malicious actions.
Source: CAPEC™ 473
Related ASVS Requirements
ASVS (5.0): 11.1.1, 11.1.2, 11.1.3, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.2, 11.4.3, 11.4.4, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 16.3.3, 6.8.2, 9.1.1, 9.1.2, 9.1.3