Microsoft admits it signed a malicious driver called “Netfilter” targeting gaming environments; the rootkit malware was observed communicating with Chinese IPs
Ax Sharma / BleepingComputer : Source: Microsoft Security … .
BleepingComputerAx Sharma
Context & Ripple Effects
The Netfilter disclosure is an early warning that Microsoft’s signing pipeline can be used to give malware kernel-level legitimacy in a targeted environment. Later coverage shows the issue was not isolated to one incident: Microsoft acknowledged driver-blocklist updates were not being properly applied, limiting a key response to malicious or vulnerable drivers.
The subsequent report that certified Windows drivers were used to sign malware extends the arc from a single bad signature to the integrity of the certification ecosystem. The observed Chinese IP communications are an operational indicator, not attribution.
First-order effects
Gaming-environment users targeted by Netfilter faced a signed rootkit communicating externally, while Microsoft had to account for a malicious driver passing through its signing process.
Microsoft’s driver signature became a liability rather than a trust signal for systems that accepted Netfilter.
Second-order effects
A driver blocklist is less effective when endpoints do not reliably receive its updates, as Microsoft later acknowledged, leaving defenders dependent on a control that may not be present.
Hardware developers and security teams must treat driver certification as an abuse target after reports that certified drivers were used to sign malware.
Third-order effects
The pattern points to Windows kernel-driver trust moving from a certification-only model toward one that also depends on rapid revocation and dependable blocklist distribution.
If signed-driver abuse persists, Microsoft’s certification program becomes a security boundary whose operational enforcement matters as much as its initial approval process.
The trend: Kernel-level malware is increasingly exploiting software trust channels, making certificate governance and post-certification blocking central to endpoint security.
☢️Network filter rootkit that connects to this IP in China: hxxp://110.42.4.180:2081/u It does not look like Moriya (signature will be corrected asap) File is signed by Microsoft. #rootkit #netfilter https://www.virustotal.com/...
Microsoft admits it signed the malicious #Netfilter driver seen communicating with Chinese C2 IPs, first spotted by @struppigel of @GDATA. No certificates were stolen, but the incident exposes legit weakness in Windows Hardware Compatibility Program. https://www.bleepingcomputer.…
oh, ok, cool. so “the signing certificates were not exposed” but that means y'all just straight up signed and distributed drivers that contained malware. definitely makes me feel better. https://msrc-blog.microsoft.com/ ...
WTF! 🤯😠"The mishap seems to have resulted from the threat actor following Microsoft's process to submit the malicious Netfilter drivers, and managing to acquire the Microsoft-signed binary in a legitimate manner" https://www.bleepingcomputer.com/ ...
“Microsoft is investigating a malicious actor distributing malicious drivers within gaming environments. The actor submitted drivers for certification through the Windows Hardware Compatibility Program. The drivers were built by a third party.” https://msrc-blog.microsoft.com/ ..…
@MalwareTechBlog That's Microsoft's spin. I have a bunch more of these which are signed, but here's one they're talking about. https://www.gdatasoftware.com/ ...
‘"We have suspended the account and reviewed their submissions for additional signs of malware," said Microsoft yesterday.’ No, you immediately revoke ALL their certificates. You submit malicious code? All your code is considered malicious. https://www.bleepingcomputer.com/ ...