City
Epaper

Microsoft admits to signing rootkit malware in supply-chain fiasco

By IANS | Updated: June 28, 2021 11:05 IST

San Francisco, June 28 Tech giant Microsoft has now confirmed signing a malicious driver being distributed within gaming ...

Open in App

San Francisco, June 28 Tech giant Microsoft has now confirmed signing a malicious driver being distributed within gaming environments.

According to Bleeping Computers, this driver, called "Netfilter," is a rootkit that was observed communicating with Chinese command-and-control (C2) IPs.

G Data malware analyst Karsten Hahn first took notice of this event last week and was joined by the wider infosec community in tracing and analysing the malicious drivers bearing the seal of Microsoft.

This incident has once again exposed threats to software supply-chain security, except this time it stemmed from a weakness in Microsoft's code-signing process.

Microsoft said it is actively investigating this incident, although thus far, there is no evidence that stolen code-signing certificates were used.

The mishap seems to have resulted from the threat actor following Microsoft's process to submit the malicious Netfilter drivers and managing to acquire the Microsoft-signed binary in a legitimate manner.

"Microsoft is investigating a malicious actor distributing malicious drivers within gaming environments," the company was quoted as saying by the website.

"We have suspended the account and reviewed their submissions for additional signs of malware," said Microsoft yesterday.

According to Microsoft, the threat actor has mainly targeted the gaming sector specifically in China with these malicious drivers and there is no indication of enterprise environments having been affected so far.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Bleeping computersKarsten hahnchinamicrosoftSan FranciscoSan francisco bayJose d'sa
Open in App

Related Stories

NationalAir India Flight From San Francisco to Mumbai Suffers Technical Snag; Passengers Deplaned at Kolkata Airport (Watch Videos)

TechnologyIT Layoffs 2025: Microsoft, Google, Apple Among 284 Tech Companies That Cut Jobs in First 5 Months

InternationalEarthquake of Magnitude 4.5 Hits China, Tremors Felt in Myanmar

TechnologyMicrosoft Layoffs: Satya Nadella-led Company Sacks Over 6,000 Employees Across Key Positions

InternationalPakistan Engaged in Diplomatic Contacts With Iran, China and Others to De-Escalate Situation: Pak Defence Minister

Technology Realted Stories

MumbaiMumbai Metro Line 3 Update: Aqua Line Integrates with ONDC, Enables Easy QR Ticket Booking via Seven Apps

TechnologyIIT Madras breaks into global top 200 in QS world rankings 2026

TechnologyIndia’s high-activity micro markets to drive 80 pc of office demand and supply in few years

TechnologyMatter of immense pride: Education Minister Pradhan hails QS World University Rankings 2026

TechnologyQS Rankings 2026 features record 54 Indian institutes, IIT Delhi tops