/?pid=microsoft-digitally-signs-malicious-rootkit-driver-22704

Updated:04:48 AM EST Jan 30


this is ggmania.com subsite Microsoft digitally signs malicious rootkit driver - TechAmok

Microsoft digitally signs malicious rootkit driver - [security]
05:37 PM EDT - Jun,29 2021 - post a comment

Microsoft gave its digital imprimatur to a rootkit that decrypted encrypted communications and sent them to attacker-controlled servers, the company and outside researchers said. The blunder allowed the malware to be installed on Windows machines without users receiving a security warning or needing to take additional steps. For the past 13 years, Microsoft has required third-party drivers and other code that runs in the Windows kernel to be tested and digitally signed by the OS maker to ensure stability and security. Without a Microsoft certificate, these types of programs can't be installed by default.

Earlier this month, Karsten Hahn, a researcher at security firm G Data, found that his company's malware detection system flagged a driver named Netfilter. He initially thought the detection was a false positive because Microsoft had digitally signed Netfilter under the company's Windows Hardware Compatibility Program. After further testing, Hahn determined that the detection wasn't a false positive. He and fellow researchers decided to figure out precisely what the malware does. "The core functionality seems to be eavesdropping on SSL connections," reverse engineer Johann Aydinbas wrote on Twitter. "In addition to the IP redirecting component, it also installs (and protects) a root certificate to the registry." A rootkit is a type of malware that is written in a way that prevents it from being viewed in file directories, task monitors, and other standard OS functions. A root certificate is used to authenticate traffic sent through connections protected by the Transport Layer Security protocol, which encrypts data in transit and ensures the server to which a user is connected is genuine and not an imposter. Normally, TLS certificates are issued by a Windows-trusted certificate authority (or CA). By installing a root certificate in Windows itself, hackers can bypass the CA requirement. Microsoft's digital signature, along with the root certificate the malware installed, gave the malware stealth and the ability to send decrypted TLS traffic to hxxp://110.42.4.180:2081/s.

In a brief post from Friday, Microsoft wrote, "Microsoft is investigating a malicious actor distributing malicious drivers within gaming environments. The actor submitted drivers for certification through the Windows Hardware Compatibility Program. The drivers were built by a third party. We have suspended the account and reviewed their submissions for additional signs of malware." The post said that Microsoft has found no evidence that either its signing certificate for the Windows Hardware Compatibility Program or its WHCP signing infrastructure had been compromised. The company has since added Netfilter detections to the Windows Defender AV engine built into Windows and provided the detections to other AV providers. The company also suspended the account that submitted Netfilter and reviewed previous submissions for signs of additional malware.

Short overview of recent news articles

NVIDIA GeForce 591.86 WHQL Driver (Jan,30 2026 )

iOS 26.3-Important New iPhone Location Privacy Feature Coming Soon (Jan,30 2026 )

I Made the Ultimate Steam Machine Before Valve (Jan,29 2026 )

Wardriver - Official Trailer (2026) Dane DeHaan, Sasha Calle, (Jan,29 2026 )

Apple Intros Improved AirTag (Jan,28 2026 )

US Version of TikTok off to Bumpy Start; Competitors Surge (Jan,28 2026 )

Google Chrome no longer needs you, as Gemini takes the driving seat (Jan,28 2026 )

Premium Subscriptions Coming to Facebook, Instagram, WhatsApp (Jan,27 2026 )

Windows 11 Best For Gaming? Windows 11 25H2 vs. Windows 10 (Jan,25 2026 )

Microsoft Says Uninstall This Windows Update Immediately (KB5077744 (Jan,24 2026 )

Xbox Developer Direct Livestream 2026 | Fable, Forza Horizon 6, (Jan,22 2026 )

Iridium Begins Testing its own Satellite Service for Phones (Jan,22 2026 )

AMD Releases Adrenalin Edition 26.1.1 WHQL Drivers (Jan,22 2026 )

AI in 2050 (Jan,18 2026 )

iOS 26.2 Fixes Major Security Flaws (Jan,17 2026 )

Google Links its AI to Your Gmail and Photos for "Personal (Jan,17 2026 )

Fastest Koenigsegg v Fastest Bugatti: DRAG RACE (Jan,17 2026 )

Creating a 48GB NVIDIA RTX 4090 GPU (Jan,17 2026 )

CES was frickin weird, guys (Jan,14 2026 )

Lee Cronin's The Mummy - Official Teaser Trailer (2026) Jack (Jan,12 2026 )

Ferrari SF90 XX v Xiaomi SU7 Ultra: DRAG RACE (Jan,12 2026 )

Welcome to the Wasteland - Fallout (American TV series) fan video (Jan,10 2026 )

GOOD LUCK, HAVE FUN, DON'T DIE Trailer 2 (2026) Sam Rockwell (Jan,09 2026 )

NVIDIA Releases GeForce 591.74 WHQL Drivers with DLSS 4.5 Support (Jan,07 2026 )

Predator: Badlands Exclusive Deleted Scene (2025) (Jan,07 2026 )

Greenland 2: Migration - Official Trailer 3 (2026) Gerard Butler, (Jan,06 2026 )

The Best Laptops of 2025 - For Gaming, Creators & Students! (Jan,05 2026 )

Punkt Updates its Privacy-Focused Smartphone (Jan,05 2026 )

Clicks Launches New Ways to Add a Physical Keyboard to Your Life (Jan,05 2026 )

Building a PC for the First Time (Jan,05 2026 )

Building a PC in 2026 (Jan,03 2026 )

I want this phone so bad... - Samsung Galaxy Z TriFold (Jan,02 2026 )

The Real Finewine Strikes Again: Ryzen 5600X, 5700X & 5800XT Revisit (Jan,02 2026 )

Nokia N8 Symbian Re-Awakened With Passion (Jan,02 2026 )

Europe Forces Apple to Open up More of iOS (Jan,02 2026 )

Must have Privacy and Security Tweaks: 2026 Edition (Jan,02 2026 )

How Did RAM Get So Expensive?! (Jan,01 2026 )

GeForce RTX 5090 prices to soar to $5,000 as NVIDIA and AMD prep GPU (Dec,31 2025 )

Hacker arrested for KMSAuto malware campaign with 2.8 million (Dec,30 2025 )

Killer Whale - Official Trailer (2026) Virginia Gardner, Mel (Dec,29 2025 )

NVIDIA Showed Me Their Supercomputer (Dec,28 2025 )

2026 CPU Launches! AMD, Intel & NVIDIA: Buy Now or Wait? (Dec,28 2025 )

Disable this Windows Feature that Secretly Eats Up RAM! (Dec,27 2025 )

New Windows 11 vs Old Malware: Will it survive? (Dec,27 2025 )

Samsung TriFold Durability Test: We found the limit (Dec,27 2025 )

TRUST WALLET CONFIRMS SECURITY BREACH (Dec,26 2025 )

Xiaomi 17 Ultra Leads And Samsung To Follow With A 10 Percent Price (Dec,26 2025 )

Merry Christmas Gaming Insanity (Dec,25 2025 )

Battlefield 6 - Official PS5 Features Trailer (Dec,24 2025 )

NVIDIA GeForce Hotfix Driver 591.67 Released (Dec,24 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs