$ 117,972.2
€ 101,382.6
£ 87,849.8
¥ 17,575,386.9
CZK 2,497,977.0
BTC
-0.46 %
$ 3,705.63
€ 3,184.43
£ 2,759.24
¥ 551,679.6
CZK 78,236.3
ETH
4.10 %
$ 3.51
€ 3.02
£ 2.61
¥ 523.26
CZK 74.51
XRP
2.47 %
$ 0.4691
€ 0.4036
£ 0.3491
¥ 69.97
CZK 10.04
XLM
1.26 %
/?pid=22704

Updated:03:26 AM EDT Jul 20


this is ggmania.com subsite Microsoft digitally signs malicious rootkit driver - TechAmok

Microsoft digitally signs malicious rootkit driver - [security]
05:37 PM EDT - Jun,29 2021 - post a comment

Microsoft gave its digital imprimatur to a rootkit that decrypted encrypted communications and sent them to attacker-controlled servers, the company and outside researchers said. The blunder allowed the malware to be installed on Windows machines without users receiving a security warning or needing to take additional steps. For the past 13 years, Microsoft has required third-party drivers and other code that runs in the Windows kernel to be tested and digitally signed by the OS maker to ensure stability and security. Without a Microsoft certificate, these types of programs can't be installed by default.

Earlier this month, Karsten Hahn, a researcher at security firm G Data, found that his company's malware detection system flagged a driver named Netfilter. He initially thought the detection was a false positive because Microsoft had digitally signed Netfilter under the company's Windows Hardware Compatibility Program. After further testing, Hahn determined that the detection wasn't a false positive. He and fellow researchers decided to figure out precisely what the malware does. "The core functionality seems to be eavesdropping on SSL connections," reverse engineer Johann Aydinbas wrote on Twitter. "In addition to the IP redirecting component, it also installs (and protects) a root certificate to the registry." A rootkit is a type of malware that is written in a way that prevents it from being viewed in file directories, task monitors, and other standard OS functions. A root certificate is used to authenticate traffic sent through connections protected by the Transport Layer Security protocol, which encrypts data in transit and ensures the server to which a user is connected is genuine and not an imposter. Normally, TLS certificates are issued by a Windows-trusted certificate authority (or CA). By installing a root certificate in Windows itself, hackers can bypass the CA requirement. Microsoft's digital signature, along with the root certificate the malware installed, gave the malware stealth and the ability to send decrypted TLS traffic to hxxp://110.42.4.180:2081/s.

In a brief post from Friday, Microsoft wrote, "Microsoft is investigating a malicious actor distributing malicious drivers within gaming environments. The actor submitted drivers for certification through the Windows Hardware Compatibility Program. The drivers were built by a third party. We have suspended the account and reviewed their submissions for additional signs of malware." The post said that Microsoft has found no evidence that either its signing certificate for the Windows Hardware Compatibility Program or its WHCP signing infrastructure had been compromised. The company has since added Netfilter detections to the Windows Defender AV engine built into Windows and provided the detections to other AV providers. The company also suspended the account that submitted Netfilter and reviewed previous submissions for signs of additional malware.


Add your comment (free registrationrequired)

Short overview of recent news articles

Jul,20 2025 THE BEST VW GOLF GTI I've Driven! Proper ClubSport
Jul,19 2025 Intel Core Ultra 9 275HX vs AMD Ryzen 9 9955HX - Which CPU is Best?
Jul,18 2025 LAMBORGHINI REVUELTO V12 // 370KMH REVIEW on UNLIMITED AUTOBAHN!
Jul,18 2025 Mortal Kombat II - Official Trailer
Jul,17 2025 Stranger Things 5 - Official Teaser
Jul,14 2025 Google Is Selling Fake Products - WAN Show July 11, 2025
Jul,12 2025 Hacked by playing Call of Duty WW2 on Gamepass?
Jul,12 2025 2025 VW Golf GTE // TOP SPEED REVIEW on AUTOBAHN
Jul,11 2025 NEW Audi RS3 v cheapest used RS3: DRAG RACE
Jul,10 2025 A critical security vulnerability in Microsoft Remote Desktop Client
Jul,10 2025 Samsung Z Fold/Flip 7 Impressions: Major Upgrades!
Jul,08 2025 Gmail's latest feature helps you get rid of those pesky emails from
Jul,06 2025 I'm an idiot and still made top 5... here's how
Jul,05 2025 The Fantastic Four: First Steps - Official 'Lift Off' Teaser
Jul,04 2025 Samsung Galaxy Z Fold 7 - Hands on Look
Jul,04 2025 RTX 5070 Ti vs RTX 5080 - Is 5080 Gaming Laptop Worth More $$$?
Jul,04 2025 FIRST DRIVE: Praga Bohema - Crazy Hypercar Driven!
Jul,03 2025 Ballerina - Exclusive John Wick Deleted Scene (2025) Keanu Reeves,
Jul,03 2025 Call of Duty: WWII - Remote Code Execution Warning (PC Game Pass)
Jul,02 2025 1014HP Lamborghini REVUELTO 369KMH TOP SPEED POV on AUTOBAHN
Jul,01 2025 Nvidia Drivers (V 576.80 vs V 576.88) - Test In 12 Games - RTX 4060
Jun,30 2025 AMD Adrenalin 25.6.3 Driver Is Available
Jun,30 2025 NVIDIA GeForce RTX 5080 SUPER Could Feature 24 GB Memory, Increased
Jun,29 2025 Guess What Nvidia Did THIS Time
Jun,28 2025 The 10 Best Dinosaur Movies of All Time
Jun,28 2025 Microsoft officially confirms that Windows 11 version 25H2 is coming
Jun,26 2025 Eddington - Official Trailer 2 (2025) Joaquin Phoenix, Pedro Pascal
Jun,25 2025 Microsoft Say System Restore Points Now Expire After 60 Days
Jun,25 2025 Facebook, Netflix, and Microsoft Websites Hijacked to Insert Fake
Jun,24 2025 I put a $3000 GPU in my Average PC... It Was a Mistake
Jun,24 2025 Best External SSD for Mac 2025: After Weeks of Testing, Here's What
Jun,23 2025 Mostly boob jokes this week (RTX 5090 DD) - Tech News June 22
Jun,21 2025 Superman - Official 30 Second Spot (2025)
Jun,21 2025 'The fastest road car I've ever been in!' - Ferrari F80 track day
Jun,20 2025 CPU SCAM: AMD Ryzen 9800X3D Counterfeits & Fraud
Jun,19 2025 28 Years Later Review
Jun,18 2025 HW News - NVIDIA "N1x" CPU Leak, ASUS Xbox ROG Ally, More Intel
Jun,17 2025 NVIDIA GeForce 576.80 WHQL Driver
Jun,16 2025 The Fantastic Four: First Steps - Official 'H.E.R.B.I.E.' Teaser
Jun,15 2025 Huawei Maextro S800 First Look - A True BMW & Mercedes Killer?
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs