{"id":1175433,"date":"2023-08-25T09:17:24","date_gmt":"2023-08-25T13:17:24","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1175433"},"modified":"2023-08-25T09:17:24","modified_gmt":"2023-08-25T13:17:24","slug":"microsoft-signing-keys-keep-getting-hijacked-to-the-delight-of-chinese-threat-actors","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1175433","title":{"rendered":"Microsoft signing keys keep getting hijacked, to the delight of Chinese threat actors"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/08\/error-message-800x600-1.jpg\" alt=\"Microsoft signing keys keep getting hijacked, to the delight of Chinese threat actors\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/error-message.jpg\" class=\"enlarge-link\" data-height=\"750\" data-width=\"1000\">Enlarge<\/a> (credit: Getty Images)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>In July, security researchers revealed a sobering discovery: hundreds of pieces of malware used by multiple hacker groups to infect Windows devices had been digitally signed and validated as safe by Microsoft itself. On Tuesday, a different set of researchers made a similarly solemn announcement: Microsoft\u2019s digital keys had been hijacked to sign yet more malware for use by a previously unknown threat actor in a supply-chain attack that infected roughly 100 carefully selected victims.<\/p>\n<p>The malware, researchers from Symantec\u2019s Threat Hunter Team <a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/carderbee-software-supply-chain-certificate-abuse\">reported<\/a>, was digitally signed with a certificate for use in what is alternatively known as the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/dashboard\/hardware-program-register\">Microsoft Windows Hardware Developer Program<\/a> and the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/dashboard\/get-started-dashboard-submissions\">Microsoft Windows Hardware Compatibility Program<\/a>. The program is used to certify that device drivers\u2014the software that runs deep inside the Windows kernel\u2014come from a known source and that they can be trusted to securely access the deepest and most sensitive recesses of the operating system. Without the certification, drivers are ineligible to run on Windows.<\/p>\n<h2>Hijacking keys to the kingdom<\/h2>\n<p>Somehow, members of this hacking team\u2014which Symantec is calling Carderbee\u2014managed to get Microsoft to digitally sign a type of malware known as a rootkit. Once installed, rootkits become what\u2019s essentially an extension of the OS itself. To gain that level of access without tipping off end-point security systems and other defenses, the Carderbee hackers first needed its rootkit to receive the Microsoft seal of approval, which it got after Microsoft signed it.<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1963184#p3\">Read 15 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1963184&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1963184\" target=\"_blank\" rel=\"noopener\">Microsoft signing keys keep getting hijacked, to the delight of Chinese threat actors<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Getty Images) In July, security researchers revealed a sobering discovery: hundreds of pieces of malware used by multiple hacker groups to infect Windows devices had been digitally signed and validated as safe by Microsoft itself. On Tuesday, a &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1175433\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1175434,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1175433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1175433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1175433"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1175433\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1175434"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1175433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1175433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1175433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}