Leaked stolen Nvidia cert can sign Windows malware

An Nvidia code-signing certificate was among the mountain of files stolen and leaked online by criminals who ransacked the GPU giant’s internal systems.

At least two binaries not developed by Nvidia, but signed this week with its stolen cert, making them appear to be Nvidia programs, have appeared in malware sample database VirusTotal.

This leak means sysadmins should take steps, or review their security policies and defenses, to ensure code recently signed by the rogue cert is detected and blocked as it is most likely going to be malicious. This can be done through Windows configuration, network filtering rules, or whatever you use to police your organization.

Computer security bod Bill Demirkapi – who we’ve featured before on these pages – tweeted a warning about the certificate potentially being able to be used to sign Windows kernel-level driver files:

As part of the #NvidiaLeaks, two code signing certificates have been compromised. Although they have expired, Windows still allows them to be used for driver signing purposes. See the talk I gave at BH/DC for more context on leaked certificates: https://t.co/UWu3AzHc66 pic.twitter.com/gCrol0BxHd

— Bill Demirkapi (@BillDemirkapi) March 3, 2022

In later tweets he added that Windows will accept drivers signed with certificates issued prior to July 29, 2015 without a timestamp. Microsoft’s Windows driver signing policy corroborates this, stating the operating system will run drivers “signed with an end-entity certificate issued prior to July 29th 2015 that chains to a supported cross-signed CA”.

The leaked Nvidia certificate is just such a creature, having expired in 2014. Code signed with this cert will, in the right conditions, be accepted by Windows even though the certificate has expired. Another Nvidia cert was leaked though expired after the cut-off date.

We asked Microsoft what steps would it be willing to take to ensure Windows blocks all code signed by the 2014 cert since its leak. A spokesperson told us: “We are looking into these new claims and we will do what is necessary to keep our customers protected.”

Infosec bod Kevin Beaumont spotted some folks have been signing their own driver code with Nvidia’s private 2014 cert and uploading it to VirusTotal to check if antivirus scanners accepted it. He posted on Twitter:

VirusTotal search if you want ’em

ls:”2022-03-01T00:00:00+” signature:43BB437D609866286DD839E1D00309F5 p:1+ tag:signed

.sys (drivers) load fine in Windows 10/11 still, even when signed with expired cert.

Threat actors started on 1st March, a day after torrent posted. pic.twitter.com/S6pCfgV8hb

— Kevin Beaumont (@GossiTheDog) March 4, 2022

The move to allow such drivers was a backwards compatibility effort (per an MSDN post from 2015, introducing Windows 10 build 1607) to prevent a then-new Windows 10 feature from causing problems with previously unsigned drivers.

We note that a good number of antivirus scanners, tested by VirusTotal on uploaded samples, are now seemingly catching code signed by the rogue Nvidia certificate, so it may be that your AV engine will automatically block it.

The crooks who compromised Nvidia’s internal systems to steal and leak the certificate – among many other files, including credentials, secret source code, and documentation – call themselves Lapsus$, and are seemingly trying to blackmail Nvidia into removing cryptomining limit from its GPU firmware. Last year, for its RTX 30-series graphics cards, Nvidia introduced a technology into their drivers called Lite Hash Rate, or LHR for short.

LHR cripples cryptocurrency mining. By nerfing the cards’ cryptomining performance, Nvidia hoped to make its graphical processing units less attractive to miners, leaving more hardware available to gamers, in theory, and others who actually want graphics performance rather than pure hash rates.

Lapsus$, according to the group’s Telegram page, are threatening Nvidia with the public release of more internal materials and details of chip blueprints unless the company promises to remove LHR. It seems wholly implausible that Nvidia would give in to such blackmail. The gang also wants Nvidia to open-source its drivers for Macs, Linux, and Windows PCs.

According to Have I Been Pwned, within the leaked data are “over 70,000 employee email addresses and NTLM password hashes, many of which were subsequently cracked and circulated within the hacking community.”

In a statement Nvidia previously said: “We are aware that the threat actor took employee passwords and some Nvidia proprietary information from our systems and has begun leaking it online. Our team is working to analyze that information.” It is maintaining an incident response page here. ®

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
A new tragedy in the family of mezzo-soprano Maria Macsim Nicoară.  It's mourning, the father of the late artist also died thumbnail

A new tragedy in the family of mezzo-soprano Maria Macsim Nicoară. It's mourning, the father of the late artist also died

O nouă tragedie s-a abătut asupra familiei greu încercate ale mezzosopranei Maria Maria Macsim Nicoară. Tatăl celebrei cântărețe a murit la mai puțin de un an de la decesul acesteia. Tatăl mezzosopranei Maria Macsim Nicoară a murit Nouă tragedie în familia mezzosopranei Maria Macsim Nicoară. Tatăl artistei s-a stins acum, la mai puțin de un…
Read More
The best Windows Photos feature is finally coming back thumbnail

The best Windows Photos feature is finally coming back

Image: Microsoft Microsoft is finally, thankfully, reinstating the Spot Fix feature in Windows 11’s Photos app. I’m mildly obsessed with the Photos app. I’ve been enraged that you can’t use Paint3D’s Magic Select tool to edit out backgrounds. I’ve fumed at Photos’ instability, mildly praised Microsoft for fixing it, then wondered why there are two
Read More
Coinbase eliminates transactions fees for its crypto debit card thumbnail

Coinbase eliminates transactions fees for its crypto debit card

Home News Computing (Image credit: Coinbase) Coinbase has announced that it has removed transaction fees for its Coinbase Card (opens in new tab) to allow customers to more easily spend their cryptocurrencies (opens in new tab).The popular cryptocurrency exchange (opens in new tab) is reimagining the crypto spending and earning experience by removing transaction fees…
Read More
'Dirty Pipe' Linux vulnerability discovered thumbnail

‘Dirty Pipe’ Linux vulnerability discovered

On Monday, a cybersecurity researcher released the details of a Linux vulnerability that allows an attacker to overwrite data in arbitrary read-only files.The vulnerability -- CVE-2022-0847 -- was discovered by Max Kellermann in April 2021, but it took another few months for him to figure out what was actually happening.  Kellermann explained that the vulnerability…
Read More
New CBN governor faces an uphill task in tackling inflation thumbnail

New CBN governor faces an uphill task in tackling inflation

The Nigerian Senate has confirmed the nomination of Yemi Cardoso as the 11th governor of the country’s central bank. The new CBN governor is tasked with tackling record inflation and saving a battered currency. The Nigerian Senate on Tuesday confirmed Yemi Cardoso as the next governor of Nigeria’s Central Bank after an hours-long screening process.
Read More
Index Of News
Total
0
Share