{"id":285783,"date":"2021-06-28T19:04:47","date_gmt":"2021-06-28T16:04:47","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/after-approving-rootkit-malware-microsoft-will-refine-code-signing-process-review-geek\/"},"modified":"2021-06-28T19:04:47","modified_gmt":"2021-06-28T16:04:47","slug":"after-approving-rootkit-malware-microsoft-will-refine-code-signing-process-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/after-approving-rootkit-malware-microsoft-will-refine-code-signing-process-review-geek\/","title":{"rendered":"#After Approving Rootkit Malware, Microsoft Will Refine Code Signing Process \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#After <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>roving Rootkit Malware, Microsoft Will Refine Code Signing Process \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage wp-image-90416 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/06\/52824bb2.png?width=1200\" alt=\"Microsoft logo at the company's office building located in Silicon Valley south San Francisco bay area\" width=\"1920\" height=\"1080\" data-crediturl=\"https:\/\/www.shutterstock.com\/image-photo\/may-3-2018-sunnyvale-ca-usa-1083507680\" data-credittext=\"Sundry Photography\/Shutterstock.com\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/may-3-2018-sunnyvale-ca-usa-1083507680\">Sundry Photography\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p><span>Microsoft <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.engadget.com\/microsoft-signed-netfilter-malware-driver-164228266.html\"><span>signed off<\/span><\/a><span> on a driver that contains rootkit malware. Despite having processes and checkpoints\u2014like code signing and the Windows Hardware Compatibility Program (WHCP)\u2014in place to prevent such events from happening, the driver still managed to pass through.<\/span><\/p>\n<p><span>The third-party Windows driver, Netfilter, was observed communicating with Chinese command-and-control IPs. Netfilter was distributed within the gaming community. It was first detected by G Data malware analyst Karsten Hahn (and soon further vetted by the infosec community at large and <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-admits-to-signing-rootkit-malware-in-supply-chain-fiasco\/\"><i><span>Bleeping Computer<\/span><\/i><\/a><span>), who im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>tely shared notice of the breach <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/struppigel\/status\/1405483373280235520\"><span>on Twitter<\/span><\/a><span> and notified Microsoft.<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\u2622\ufe0fNetwork filter rootkit that connects to this IP in China:<br \/>hxxp:\/\/110.42.4.180:2081\/u<\/p>\n<p>It does not look like Moriya (signature will be corrected asap)<\/p>\n<p>File is signed by Microsoft.<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/rootkit?src=hash&amp;ref_src=twsrc%5Etfw\">#rootkit<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/hashtag\/netfilter?src=hash&amp;ref_src=twsrc%5Etfw\">#netfilter<\/a><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/lhvmmgHn6w\">https:\/\/t.co\/lhvmmgHn6w<\/a><\/p>\n<p>\u2014 Karsten Hahn (@struppigel) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/struppigel\/status\/1405483373280235520?ref_src=twsrc%5Etfw\">June 17, 2021<\/a><\/p>\n<\/blockquote>\n<p><span>Though Microsoft has <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/90415&amp;murl=https%3A%2F%2Fmsrc-blog.microsoft.com%2F2021%2F06%2F25%2Finvestigating-and-mitigating-malicious-drivers%2F\"><span>confirmed<\/span><\/a><span> that it did, indeed, sign off on the driver, there is no clear information yet regarding how the driver made it through the company\u2019s certificate signing process. Microsoft is currently investigating and said it \u201cwill be sharing an update on how we are refining our partner access policies, validation and the signing process to further enhance our protections.\u201d<\/span><\/p>\n<p><span>Currently, there is no evidence that the malware writers stole certificates, or that the activity can be attributed to a nation-state actor. Microsoft also noted that the malware has had a limited impact, taking aim at <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/game\/\" data-internallinksmanager029f6b8e52c=\"7\" title=\"Game\" target=\"_blank\" rel=\"noopener\">game<\/a>rs and not enterprise users. \u201cWe have suspended the account and reviewed their submissions for additional signs of malware,\u201d Microsoft shared in a <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/90415&amp;murl=https%3A%2F%2Fmsrc-blog.microsoft.com%2F2021%2F06%2F25%2Finvestigating-and-mitigating-malicious-drivers%2F\"><span>blog update<\/span><\/a><span>.<\/span><\/p>\n<p><span>Despite the malware seeming to have little to no impact, and Microsoft eagerly working to resolve the issue and refine its code signing process, the incident has nonetheless disrupted user trust in Microsoft. The average user depends on these certificates and checkpoints to have a way to know that updates and new drivers are safe to install. This disruption could make users wary of future downloads for some time to come.\u00a0<\/span><\/p>\n<p><small><span>via <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.engadget.com\/microsoft-signed-netfilter-malware-driver-164228266.html\"><span>Engadget<\/span><\/a><\/small>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/90415\/after-approving-rootkit-malware-microsoft-will-refine-code-signing-process\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#After Approving Rootkit Malware, Microsoft Will Refine Code Signing Process \u2013 Review Geek&#8221; Sundry Photography\/Shutterstock.com Microsoft signed off on a driver that contains rootkit malware. Despite having processes and checkpoints\u2014like code signing and the Windows Hardware Compatibility Program (WHCP)\u2014in place to prevent such events from happening, the driver still managed to pass through. The third-party&#8230;<\/p>\n","protected":false},"author":1,"featured_media":285784,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/06\/52824bb2.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-285783","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/285783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=285783"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/285783\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/285784"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=285783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=285783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=285783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}