A driver containing rootkit malware was certified by Microsoft

Image for A driver containing rootkit malware was certified by Microsoft
(Image credit: Pixabay)

Microsoft tests drivers before assigning them a digital certificate that approves them to be installed by default. Somehow, a driver called Netfilter that redirects traffic to an IP in China and installs a root certificate to the registry managed to make it through that testing without being detected as malware.

Karsten Hahn, a malware analyst at G Data, found the malicious driver and notified Microsoft, "who promptly added malware signatures to Windows Defender and are now conducting an internal investigation." Microsoft also suspended the account that submitted the driver, and is currently going over their previous submissions.

Microsoft's security response center team described the malware's activity as "limited to the gaming sector specifically in China" and explained its purpose: "The actor's goal is to use the driver to spoof their geo-location to cheat the system and play from anywhere. The malware enables them to gain an advantage in games and possibly exploit other players by compromising their accounts through common tools like keyloggers."

How did this happen? Right now, nobody knows. Windows users are advised, "There are no actions customers should take other than follow security best practices and deploy Antivirus software such as Windows Defender for Endpoint."

Jody Macgregor
Weekend/AU Editor

Jody's first computer was a Commodore 64, so he remembers having to use a code wheel to play Pool of Radiance. A former music journalist who interviewed everyone from Giorgio Moroder to Trent Reznor, Jody also co-hosted Australia's first radio show about videogames, Zed Games. He's written for Rock Paper Shotgun, The Big Issue, GamesRadar, Zam, Glixel, Five Out of Ten Magazine, and Playboy.com, whose cheques with the bunny logo made for fun conversations at the bank. Jody's first article for PC Gamer was about the audio of Alien Isolation, published in 2015, and since then he's written about why Silent Hill belongs on PC, why Recettear: An Item Shop's Tale is the best fantasy shopkeeper tycoon game, and how weird Lost Ark can get. Jody edited PC Gamer Indie from 2017 to 2018, and he eventually lived up to his promise to play every Warhammer videogame.

Read more
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
Three Magikarp Pokémon
The FBI used self-destruct on malware infecting over 4,000 US computers, it's super effective
Marvel Rivals units - Three superheroes
Marvel Rivals admits that it accidentally banned some players for trying to run the game in a different operating system, which isn't cheating
The player wrestles with an alligator.
Delta Force has a list of tech it'll ban you to the shadowrealm for using, including the usual cheating software but also way weirder stuff like 'USB drives' [Update: The devs say it's fine, actually]
The NVIDIA stand at the Apsara Conference in Hangzhou, Zhejiang province, China, September 19, 2024. (Photo credit should read CFOTO/Future Publishing via Getty Images)
China launches an antitrust investigation into Nvidia as it wrestles with the US over AI chip sanctions
Latest in Security
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Disney World
A furry hacktivist group has breached Disney, leaked 1.1TiB of data, and says it's because Club Penguin shut down
Latest in News
A peaceful hideout with a pond in Japan
The thing I'm most excited about in Assassin's Creed Shadows is my hideout: 'a little over one acre of fully customizable land' to build on, decorate, and fill with pettable baby deer
Civilization 7 victory guide
Firaxis says it's 'entering our Sukritact Age' as it hires popular modder to work on Civilization 7
Three heroes stand against a tide of skeletons
The Hand of Fate devs are back with a bullet heaven called Hordes of Fate
Cities: Skylines 2 screenshot - street level at night
Cities: Skylines 2's asset editor remains a distant dream: Colossal Order is still working on it but says it's 'proven more technically challenging than initially anticipated'
Assassin's Creed Shadows key art.
Ubisoft reveals Assassin's Creed Shadows preload and unlock times
talk to the joneses fortnite
Epic's war against the Fortnite fraudsters sees it simultaneously name and shame alleged ne'er-do-wells as its high-powered lawyers sue them