/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft admits it signed a malicious driver called “Netfilter” targeting gaming environments; the rootkit malware was observed communicating with Chinese IPs

Ax Sharma / BleepingComputer : Source: Microsoft Security … .

BleepingComputer Ax Sharma

Context & Ripple Effects

The Netfilter disclosure is an early warning that Microsoft’s signing pipeline can be used to give malware kernel-level legitimacy in a targeted environment. Later coverage shows the issue was not isolated to one incident: Microsoft acknowledged driver-blocklist updates were not being properly applied, limiting a key response to malicious or vulnerable drivers.

The subsequent report that certified Windows drivers were used to sign malware extends the arc from a single bad signature to the integrity of the certification ecosystem. The observed Chinese IP communications are an operational indicator, not attribution.

First-order effects

  • Gaming-environment users targeted by Netfilter faced a signed rootkit communicating externally, while Microsoft had to account for a malicious driver passing through its signing process.
  • Microsoft’s driver signature became a liability rather than a trust signal for systems that accepted Netfilter.

Second-order effects

  • A driver blocklist is less effective when endpoints do not reliably receive its updates, as Microsoft later acknowledged, leaving defenders dependent on a control that may not be present.
  • Hardware developers and security teams must treat driver certification as an abuse target after reports that certified drivers were used to sign malware.

Third-order effects

  • The pattern points to Windows kernel-driver trust moving from a certification-only model toward one that also depends on rapid revocation and dependable blocklist distribution.
  • If signed-driver abuse persists, Microsoft’s certification program becomes a security boundary whose operational enforcement matters as much as its initial approval process.

The trend: Kernel-level malware is increasingly exploiting software trust channels, making certificate governance and post-certification blocking central to endpoint security.

Discussion

  • @struppigel Karsten Hahn on x
    ☢️Network filter rootkit that connects to this IP in China: hxxp://110.42.4.180:2081/u It does not look like Moriya (signature will be corrected asap) File is signed by Microsoft. #rootkit #netfilter https://www.virustotal.com/...
  • @struppigel Karsten Hahn on x
    Update by Microsoft: https://msrc-blog.microsoft.com/ ... https://twitter.com/...
  • @ax_sharma Ax Sharma on x
    Microsoft admits it signed the malicious #Netfilter driver seen communicating with Chinese C2 IPs, first spotted by @struppigel of @GDATA. No certificates were stolen, but the incident exposes legit weakness in Windows Hardware Compatibility Program. https://www.bleepingcomputer.…
  • @daedalusleto @daedalusleto on x
    oh, ok, cool. so “the signing certificates were not exposed” but that means y'all just straight up signed and distributed drivers that contained malware. definitely makes me feel better. https://msrc-blog.microsoft.com/ ...
  • @tomlawrencetech Tom on x
    WTF! 🤯😠"The mishap seems to have resulted from the threat actor following Microsoft's process to submit the malicious Netfilter drivers, and managing to acquire the Microsoft-signed binary in a legitimate manner" https://www.bleepingcomputer.com/ ...
  • @dangoodin001 Dan Goodin on x
    “Microsoft is investigating a malicious actor distributing malicious drivers within gaming environments. The actor submitted drivers for certification through the Windows Hardware Compatibility Program. The drivers were built by a third party.” https://msrc-blog.microsoft.com/ ..…
  • @ghost_motley TPM Charlie on x
    But TPM and Secure Boot will protect us... right https://twitter.com/...
  • @profwoodward Alan Woodward on x
    Here's the researchers blog which goes into detail including IoCs if yiu need them https://www.gdatasoftware.com/ ...
  • @gossithedog Kevin Beaumont on x
    @MalwareTechBlog That's Microsoft's spin. I have a bunch more of these which are signed, but here's one they're talking about. https://www.gdatasoftware.com/ ...
  • @encthenet @encthenet on x
    ‘"We have suspended the account and reviewed their submissions for additional signs of malware," said Microsoft yesterday.’ No, you immediately revoke ALL their certificates. You submit malicious code? All your code is considered malicious. https://www.bleepingcomputer.com/ ...
  • @j_opdenakker John Opdenakker on x
    Big oopsie from Microsoft. They signed a rootkit driver that redirects traffic to a Chinese IP. https://www.gdatasoftware.com/ ... #infosec