/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Security researchers say threat actors are using two of Nvidia's code-signing certificates leaked by the Lapsus$ group to sign Windows malware and hacking tools

it wants $NVDA to stop limiting crypto mining on its GPUs and to open source its drivers. The deadline was Friday. No news on if Nvidia is negotiating or if the hackers will make do on the threat to leak everything. https://twitter.com/...

BleepingComputer Lawrence Abrams

Context & Ripple Effects

This is the escalation stage of a week-long Lapsus$ campaign against Nvidia. The group claimed a 1TB haul including DLSS source code on March 1, then moved to leverage: it demanded Nvidia remove crypto mining limits and open source its GPU drivers by Friday, threatening to dump everything otherwise. Along the way, 71K+ employee credentials surfaced on Have I Been Pwned, many already cracked.

The new development is that the stolen material is now operationally live: two of Nvidia's code-signing certificates are being used to sign Windows malware and hacking tools, turning a data-theft story into an active trust problem for every Windows machine that implicitly trusts Nvidia-signed binaries.

First-order effects

  • Malware and hacking tools signed with Nvidia's certificates can present as trusted vendor software to Windows, degrading the OS's signature-based defenses for users right now.
  • Nvidia is forced into certificate revocation and reissuance, disrupting its own driver-signing pipeline while the extortion deadline over crypto mining limits and open-sourcing drivers has already passed without public word of negotiations.

Second-order effects

  • The episode hands Lapsus$ a template other groups will copy: steal signing infrastructure alongside source code, so each future breach yields both ransom leverage and immediately usable attack tooling.
  • Windows defenders and enterprise security teams must tighten scrutiny of vendor-signed binaries, raising validation costs across the software supply chain far beyond Nvidia's own ecosystem.

Third-order effects

  • If breaches keep yielding valid code-signing certificates, the industry will be pushed toward shorter-lived certificates and hardware-bound key storage, since a single leaked cert currently vouches for arbitrary malicious code.
  • Extortion is structurally shifting from pure ransom demands to policy demands — here, forcing product changes (mining limits) and engineering changes (open sourcing drivers) — meaning attackers increasingly target how companies build, not just what they hold.

The trend: Extortion groups are converting stolen corporate secrets into both working attack tools and negotiating leverage, making code-signing infrastructure a primary breach target.

Discussion

  • @kaynemcgladrey Kayne McGladrey on x
    “the stolen certificates were used to sign various malware and hacking tools, such as Cobalt Strike beacons, Mimikatz, backdoors, and remote access trojans.” https://www.bleepingcomputer.com/ ... #cybersecurity
  • @epro Emil Protalinski on x
    This ransomware group doesn't want $BTC, $ETH, or even $DOGE — it wants $NVDA to stop limiting crypto mining on its GPUs and to open source its drivers. The deadline was Friday. No news on if Nvidia is negotiating or if the hackers will make do on the threat to leak everything. h…
  • @rosesilicon @rosesilicon on x
    “Remove the mining limit or we leak switch 2 and your source code” wack world https://twitter.com/...
  • @turtlekiosk @turtlekiosk on x
    “unusual demands” they want open source nvidia drivers lol https://arstechnica.com/... https://twitter.com/...
  • @tomgara Tom Gara on x
    Hackers stole the designs for Nvidia's chips and its source code, and are threatening to release it — but they're not asking for a ransom payment! They're demanding Nvidia remove a feature on their GPUs that makes them slower at mining Ethereum https://arstechnica.com/...
  • @dinosn Nicolas Krassas on x
    NVIDIA - 71,335 breached accounts https://haveibeenpwned.com/...