Skip to main content

CertLock Trojan

A new trojan named CertLock has been identified which is designed to stop security applications from running by disallowing security vendor certificates.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new trojan named CertLock has been identified which is designed to stop security applications from running by disallowing security vendor certificates.

Affected platforms

The following platforms are known to be affected:

Threat details

When an affected user attempts to install or run security applications, the user is presented with a dialogue box stating that the vendor has been blocked from running on the affected system.

CertLock is believed to be predominantly distributed via bundled software.


Remediation steps

Type Step
  • Don’t allow users to install third-party applications which haven’t been approved.
  • Make sure that cyber-awareness training is kept up-to-date.
  • Make sure that users can only operate using the lowest privileges required for their role.
  • Make sure that malware definitions are kept up-to-date.

Last edited: 17 February 2020 11:27 am