Home / Tech News / Featured Tech News / Hackers are using Nvidia’s leaked certificates to sign malware

Hackers are using Nvidia’s leaked certificates to sign malware

LAPSUS$, the group behind the recent Nvidia cyberattack, has begun leaking more confidential data. This time around, the group leaked code signing certificates, leading to bad actors using them to sign malware. 

According to Bleepingcomputer (via TechPowerUp), it didn't take long for security researchers to find that malware developers were using the leaked code signing certificates as signatures for their creations. Virus Total has already received sample files showing Nvidia as the signing author of multiple malware and hacking tools, such as Cobalt Strike beacons, Mimikatz, backdoors, and remote access trojans.

This situation could have been prevented, but Microsoft failed to revoke the certificates as soon as they expired. As a result, Windows still accepts software signed with them. Now that this leak has occurred, Microsoft will likely finally pull the trigger and revoke the certificates as it should have done previously.

For now, the only way to prevent your system from trusting these certificates is by manually adding Windows Defender Access Control (WDAC) policies to avoid any executable using them from running on your system. However, this course of action is far from optimal, as general users may find it difficult.

Discuss on our Facebook page, HERE.

KitGuru says: Now that this has all become public, Microsoft and Nvidia will have to take further action to protect consumers from potential malware attacks. 

Become a Patron!

Check Also

Call of Duty COD

KitGuru Games: Predicting the Next Half a Decade of Call of Duty Releases

Benjamin Franklin (1706-1790) famously once said: “The three absolutes in life are death, taxes and a new Call of Duty coming out every single year”. Sure enough, the US founding father has yet to be proven wrong, with Activision and a dozen studios having ensured that come the tail-end of any given year, there will be a new COD ready to release. And so, what can we expect from the franchise later this year? What about 2027, 2028 or even 2030? By looking back at the past two decades of Call of Duty games, their trends, progression and regression, I believe I can predict the next 5 years worth of annual COD entries.