Leaked stolen Nvidia cert can sign Windows malware

An Nvidia code-signing certificate was among the mountain of files stolen and leaked online by criminals who ransacked the GPU giant’s internal systems.

At least two binaries not developed by Nvidia, but signed this week with its stolen cert, making them appear to be Nvidia programs, have appeared in malware sample database VirusTotal.

This leak means sysadmins should take steps, or review their security policies and defenses, to ensure code recently signed by the rogue cert is detected and blocked as it is most likely going to be malicious. This can be done through Windows configuration, network filtering rules, or whatever you use to police your organization.

Computer security bod Bill Demirkapi – who we’ve featured before on these pages – tweeted a warning about the certificate potentially being able to be used to sign Windows kernel-level driver files:

As part of the #NvidiaLeaks, two code signing certificates have been compromised. Although they have expired, Windows still allows them to be used for driver signing purposes. See the talk I gave at BH/DC for more context on leaked certificates: https://t.co/UWu3AzHc66 pic.twitter.com/gCrol0BxHd

— Bill Demirkapi (@BillDemirkapi) March 3, 2022

In later tweets he added that Windows will accept drivers signed with certificates issued prior to July 29, 2015 without a timestamp. Microsoft’s Windows driver signing policy corroborates this, stating the operating system will run drivers “signed with an end-entity certificate issued prior to July 29th 2015 that chains to a supported cross-signed CA”.

The leaked Nvidia certificate is just such a creature, having expired in 2014. Code signed with this cert will, in the right conditions, be accepted by Windows even though the certificate has expired. Another Nvidia cert was leaked though expired after the cut-off date.

We asked Microsoft what steps would it be willing to take to ensure Windows blocks all code signed by the 2014 cert since its leak. A spokesperson told us: “We are looking into these new claims and we will do what is necessary to keep our customers protected.”

Infosec bod Kevin Beaumont spotted some folks have been signing their own driver code with Nvidia’s private 2014 cert and uploading it to VirusTotal to check if antivirus scanners accepted it. He posted on Twitter:

VirusTotal search if you want ’em

ls:”2022-03-01T00:00:00+” signature:43BB437D609866286DD839E1D00309F5 p:1+ tag:signed

.sys (drivers) load fine in Windows 10/11 still, even when signed with expired cert.

Threat actors started on 1st March, a day after torrent posted. pic.twitter.com/S6pCfgV8hb

— Kevin Beaumont (@GossiTheDog) March 4, 2022

The move to allow such drivers was a backwards compatibility effort (per an MSDN post from 2015, introducing Windows 10 build 1607) to prevent a then-new Windows 10 feature from causing problems with previously unsigned drivers.

We note that a good number of antivirus scanners, tested by VirusTotal on uploaded samples, are now seemingly catching code signed by the rogue Nvidia certificate, so it may be that your AV engine will automatically block it.

The crooks who compromised Nvidia’s internal systems to steal and leak the certificate – among many other files, including credentials, secret source code, and documentation – call themselves Lapsus$, and are seemingly trying to blackmail Nvidia into removing cryptomining limit from its GPU firmware. Last year, for its RTX 30-series graphics cards, Nvidia introduced a technology into their drivers called Lite Hash Rate, or LHR for short.

LHR cripples cryptocurrency mining. By nerfing the cards’ cryptomining performance, Nvidia hoped to make its graphical processing units less attractive to miners, leaving more hardware available to gamers, in theory, and others who actually want graphics performance rather than pure hash rates.

Lapsus$, according to the group’s Telegram page, are threatening Nvidia with the public release of more internal materials and details of chip blueprints unless the company promises to remove LHR. It seems wholly implausible that Nvidia would give in to such blackmail. The gang also wants Nvidia to open-source its drivers for Macs, Linux, and Windows PCs.

According to Have I Been Pwned, within the leaked data are “over 70,000 employee email addresses and NTLM password hashes, many of which were subsequently cracked and circulated within the hacking community.”

In a statement Nvidia previously said: “We are aware that the threat actor took employee passwords and some Nvidia proprietary information from our systems and has begun leaking it online. Our team is working to analyze that information.” It is maintaining an incident response page here. ®

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Snart kommer Windows 11 Pro kräva ett Microsoft-konto thumbnail

Snart kommer Windows 11 Pro kräva ett Microsoft-konto

Microsoft meddelar nu att Windows 11 Pro snart kommer uppdateras så det krävs både en internetuppkoppling och ett Microsoft-konto för att installera operativsystemet.Tidigar har det varit möjligt för Windows 11 Pro-användare att hoppa över den biten ifall de inte är uppkopplade mot internet.Under 2021 började Microsoft även kräva att installationen av Windows 11 Home sker…
Read More
Apple says it will fix Studio Display camera issues with software update thumbnail

Apple says it will fix Studio Display camera issues with software update

It's currently unclear if the cause of the problem is tied to software or hardware Apple’s Studio Display has received a mixed reception from tech YouTubers, bloggers and journalists, with many citing its built-in webcam as lacklustre. Despite featuring the same 12-megapixel ultra-wide camera as the latest iPad Air, early reviews state that the shooter…
Read More
Paddle offers an alternative to Apple's payment service in iOS apps thumbnail

Paddle offers an alternative to Apple's payment service in iOS apps

После судебного решения по иску Epic Games, разрешившего использовать в приложениях для iOS альтернативные методы платежа помимо предлагаемого самой Apple, популярная среди бизнес-клиентов платёжная система Paddle предложила собственный механизм для оплаты покупок в приложениях. В пресс-релизе Paddle предложила «высококонкурентную структуру платежей» в сравнении с Apple, берущей с разработчиков за посредничество 15-30 % от суммы покупки.…
Read More
Swire Denies Attempting to Sell Miami Project as Market Slides thumbnail

Swire Denies Attempting to Sell Miami Project as Market Slides

Rendering of One Brickell City Centre (Image: The Related Companies) Ten months after starting to clear the site for an office development which is planned to be Miami’s tallest skyscraper upon completion, Swire Properties has shopped the project to potential buyers, according to a Wall Street Journal report this week, as demand for deskspace dips
Read More

Try to fix Valve’s Steam Deck at your own peril

Valve has long been a proponent of open hardware and software, but its latest video makes a case to the contrary for the upcoming Steam Deck. The game company has posted a Steam Deck teardown video that shows how to pry open the handheld console while simultaneously urging you to keep the system shut. It's…
Read More
Index Of News
Total
0
Share