/?pid=microsoft-digitally-signs-malicious-rootkit-driver-22704

Updated:02:35 AM EDT Jun 18


this is ggmania.com subsite Microsoft digitally signs malicious rootkit driver - TechAmok

Microsoft digitally signs malicious rootkit driver - [security]
05:37 PM EDT - Jun,29 2021 - post a comment

Microsoft gave its digital imprimatur to a rootkit that decrypted encrypted communications and sent them to attacker-controlled servers, the company and outside researchers said. The blunder allowed the malware to be installed on Windows machines without users receiving a security warning or needing to take additional steps. For the past 13 years, Microsoft has required third-party drivers and other code that runs in the Windows kernel to be tested and digitally signed by the OS maker to ensure stability and security. Without a Microsoft certificate, these types of programs can't be installed by default.

Earlier this month, Karsten Hahn, a researcher at security firm G Data, found that his company's malware detection system flagged a driver named Netfilter. He initially thought the detection was a false positive because Microsoft had digitally signed Netfilter under the company's Windows Hardware Compatibility Program. After further testing, Hahn determined that the detection wasn't a false positive. He and fellow researchers decided to figure out precisely what the malware does. "The core functionality seems to be eavesdropping on SSL connections," reverse engineer Johann Aydinbas wrote on Twitter. "In addition to the IP redirecting component, it also installs (and protects) a root certificate to the registry." A rootkit is a type of malware that is written in a way that prevents it from being viewed in file directories, task monitors, and other standard OS functions. A root certificate is used to authenticate traffic sent through connections protected by the Transport Layer Security protocol, which encrypts data in transit and ensures the server to which a user is connected is genuine and not an imposter. Normally, TLS certificates are issued by a Windows-trusted certificate authority (or CA). By installing a root certificate in Windows itself, hackers can bypass the CA requirement. Microsoft's digital signature, along with the root certificate the malware installed, gave the malware stealth and the ability to send decrypted TLS traffic to hxxp://110.42.4.180:2081/s.

In a brief post from Friday, Microsoft wrote, "Microsoft is investigating a malicious actor distributing malicious drivers within gaming environments. The actor submitted drivers for certification through the Windows Hardware Compatibility Program. The drivers were built by a third party. We have suspended the account and reviewed their submissions for additional signs of malware." The post said that Microsoft has found no evidence that either its signing certificate for the Windows Hardware Compatibility Program or its WHCP signing infrastructure had been compromised. The company has since added Netfilter detections to the Windows Defender AV engine built into Windows and provided the detections to other AV providers. The company also suspended the account that submitted Netfilter and reviewed previous submissions for signs of additional malware.

Short overview of recent news articles

HW News - NVIDIA "N1x" CPU Leak, ASUS Xbox ROG Ally, More Intel (Jun,18 2025 )

NVIDIA GeForce 576.80 WHQL Driver (Jun,17 2025 )

The Fantastic Four: First Steps - Official 'H.E.R.B.I.E.' Teaser (Jun,16 2025 )

Huawei Maextro S800 First Look - A True BMW & Mercedes Killer? (Jun,15 2025 )

Upgrade Windows 10 to Windows 10 LTSC Without Losing Data (Jun,14 2025 )

Squid Game: Season 3 - Final Games Trailer (Jun,14 2025 )

WWDC 2025: Everything Revealed in 9 Minutes (Jun,11 2025 )

Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws (Jun,10 2025 )

This Malware BREAKS WINDOWS! (Jun,10 2025 )

Reset Forgotten Password without Any Software, without USB drive in (Jun,10 2025 )

Microsoft Will Block Unsupported Hardware For Windows 11 (Jun,08 2025 )

Memory Wars! Apple vs Ryzen - Is Unified Memory Faster than Shared (Jun,08 2025 )

Predator: Killer of Killers - Exclusive Clip (2025) (Jun,06 2025 )

Enable Deep Effect on Samsung One Ui 7 (Jun,06 2025 )

Google Kills Off PayPal in Google Wallet (Jun,05 2025 )

Samsung's Next Flagship Foldable Will be Ultra (Jun,05 2025 )

Over 40 Malicious Chrome Extensions Mimic Popular Brands to Steal (Jun,05 2025 )

The Witcher IV - Unreal Engine 5 tech demo (Jun,03 2025 )

Nintendo Switch 2 Welcome Tour trailer (Jun,02 2025 )

Stranger Things 5 | Date Announcement | Netflix (Jun,01 2025 )

RTX 5060 Review... No wonder NVIDIA tried to stop us from talking (May,31 2025 )

Samsung Galaxy Watch 8 Classic Is Here - 7 New Updates (May,30 2025 )

Biggest Windows 11 24H2 May Update in the Main Release (May,30 2025 )

How Much Money Should You Spend on a Gaming PC? (May,29 2025 )

laud Note vs Note Pin - Which AI Voice Recorder To Choose (May,29 2025 )

Samsung One UI 8.0 vs One UI 7.0 - 25+ Changes (May,29 2025 )

SECRET CODE UPDATE for Samsung Galaxy Phone to Boost Performance & (May,28 2025 )

WhatsApp is finally available on iPad (May,27 2025 )

Simple Trick To Lower CPU Temperatures (May,27 2025 )

Alma & The Wolf - Official Trailer (2025) Ethan Embry, Li Jun Li, (May,26 2025 )

Change These Browser Security Settings NOW (May,25 2025 )

I NEED AMD to Seize This Moment - RX 9060XT (May,24 2025 )

Windows 98 with a G41 Core 2 Duo System (May,23 2025 )

Disable These Windows Settings for Better FPS! (May,23 2025 )

I Got the Golden GPU from Dubai (May,20 2025 )

Windows 10 emergency update KB5061768 fixes BitLocker boot loops - (May,19 2025 )

2025 AUDI S5 AVANT // 0-100 100-200 TOP SPEED POV & SOUND (May,19 2025 )

Jurassic World Rebirth - Official 'Alert' Teaser Trailer (2025) (May,18 2025 )

F1 25 and F1 The Movie hand in hand (May,18 2025 )

Everyone is Cooling Their PC Wrong (May,17 2025 )

M5 KILLER? Testing the MERCEDES E63S AMG! (May,16 2025 )

Samsung Fully Reveals 5.8mm-Thick Galaxy S25 Edge (May,16 2025 )

Apple Intros New Accessibility Apps, Plus Accessibility "Labels" (May,16 2025 )

Americana - Official Trailer (2025) Sydney Sweeney, Halsey, Simon (May,16 2025 )

Aston Martin x Apple CarPlay Ultra - Next generation of automotive (May,16 2025 )

Google TAG deleted 23,000+ YouTube channels in January, February, (May,15 2025 )

NVIDIA GeForce Game Ready 576.40 WHQL Driver Released (May,14 2025 )

F1 - Official Trailer #2 (2025) Brad Pitt, Damson Idris, Kerry (May,13 2025 )

The Old Guard 2 - Official Trailer (2025) Charlize Theron, KiKi (May,11 2025 )

I think I know why Ryzen 9000 Series CPUs are Dying...(!) (May,11 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs