No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Hackers Target Chinese Gamers With Microsoft-Signed Rootkit

July 13, 2023
in Protection
0
Hackers Target Chinese Gamers With Microsoft-Signed Rootkit



A new campaign targeting gaming users in China is the latest example of how threat actors are increasingly using sophisticated rootkits to hide malicious payloads, disable security tools, and maintain persistence on victim systems.

The novel rootkit in this instance has a valid Microsoft digital signature, meaning it can successfully load on systems running recent Windows versions without getting blocked or triggering any security alerts. It can download other unsigned kernel mode drivers directly into memory, including one that is engineered to shut down Windows Defender software on target systems so the threat actor can then deploy second-stage malware of their choice — and maintain persistence — on them.

Kernel Mode Driver Threat

Researchers at Trend Micro recently discovered the malicious kernel driver targeting gaming users in China and reported their discovery to Microsoft last month. They believe the unknown threat actor behind it was also behind a similar 2021 rootkit for monitoring and redirecting Web traffic, dubbed FiveSys, that also targeted the Chinese gaming sector.

The new malware is one of a growing number of Microsoft-signed kernel drivers that security researchers have discovered over the past two years. Other examples include PoorTry, a rootkit that Mandiant reported last December, which threat actors are using in different ways including to deploy ransomware; and NetFilter for IP redirection; and FiveSys. Last December, Sophos disclosed a Microsoft-signed Windows driver engineered to kill antivirus software and endpoint security tools on targeted systems. Many believe that attackers are increasingly employing such tools because of how effective endpoint tools have become at detecting threats smuggled in via other vectors.

Many of these tools have targeted the gaming sector in China for purposes like credential theft and geolocation cheating in games. But there is no reason why a threat actor wouldn’t be able to use them in other geographies and for a slew of other malicious use cases.

“Despite how complex it is to build such capabilities, it seems that current malicious actors are exhibiting competence and consistent usage of such tools, tactics, and procedures (TTPs), regardless of their final motive and objectives,” Trend Micro researchers Mahmoud Zohdy, Sherif Magdy, and Mohamed Fahmy wrote this week.

Universal Rootkit Loader

The researchers identified the new malware they discovered as a standalone kernel driver that functions as a universal rootkit loader. The first-stage driver — the Microsoft-signed one — communicates with command and communications (C2) servers using the Windows Socket Kernel, a kernel-mode network programming interface. “It uses a Domain Generating Algorithm (DGA) algorithm to generate different domains,” the three researchers said. “If it fails to resolve an address, it connects directly to fallout IPs that are hard coded inside the driver.”

The first-stage driver acts as a loader for a self-signed second-stage driver. Because the second-stage driver is downloaded via the signed first-stage driver, it bypasses the Windows native driver loader and is loaded directly into memory. Then the malware initiates a sequence of steps to maintain persistence and remove any traces of its presence from the disk.

Trend Micro said it was able to tie the new malware to the FiveSys actor because of various similarities between the two malware tools. Both the FiveSys rootkit and the second-stage rootkit associated with the new malware function to redirect Web browsing traffic to an attacker-controlled server. Both can monitor Web traffic and hook file system functions, Trend Micro said.

Rogue Developer Accounts

Microsoft has blamed the issue of Microsoft-signed malicious drivers on rogue developer accounts within its partner program. According to the company, “several developer accounts for the Microsoft Partner Center (MPC) were engaged in submitting malicious drivers to obtain a Microsoft signature.” In an advisory that accompanied its July 2023 security update announcement, the company said it has suspended all the accounts and released updates for detecting and blocking the malicious drivers.

Meanwhile, in a new twist, Cisco Talos this week said it had discovered threat actors using open source digital signature timestamp forging tools to alter the signing date on kernel mode Microsoft drivers and deploy them by the thousands. The company tied the activity to a loophole in Microsoft’s Windows driver signing policy. The policy basically specifies that Windows will not load any new kernel level drivers unless they are signed via Microsoft’s Dev Portal. The policy, however, provides an exception that allows “the signing and loading of cross-signed kernel mode drivers with signature timestamp prior to July 29, 2015,” Cisco said. Threat actors are abusing the loopholes to sign drivers, including expired ones, so they fall within the policy exemption and then are using them to deploy malware.

Editorial Team

Editorial Team

Related Posts

Protection

Five of My Favorite YouTube Channels With Free Spin Classes

June 13, 2025
How to Use Each Head on Your Massage Gun Most Effectively
Protection

How to Use Each Head on Your Massage Gun Most Effectively

June 12, 2025
iOS 26 Will Make Managing Your Battery Life Easier
Protection

iOS 26 Will Make Managing Your Battery Life Easier

June 11, 2025
Protection

Why I’m Excited About Poshmark and Facebook Marketplace Joining Forces

June 10, 2025
How to Install macOS 26 Tahoe Right Now
Protection

How to Install macOS 26 Tahoe Right Now

June 9, 2025
Samsung’s AI-Powered Galaxy Watch 7 Is $200 Right Now
Protection

Samsung’s AI-Powered Galaxy Watch 7 Is $200 Right Now

June 8, 2025
Load More
Next Post
Junior doctors in England start five-day strike with pay talks deadlocked

Junior doctors in England start five-day strike with pay talks deadlocked

Popular News

  • Bridgepoint private credit grows

    Bridgepoint private credit grows by €1.4bn as group AUM doubles since IPO

    0 shares
    Share 0 Tweet 0
  • Hackers Target Chinese Gamers With Microsoft-Signed Rootkit

    0 shares
    Share 0 Tweet 0
  • 4 Ways To Improve Your LinkedIn Presence

    0 shares
    Share 0 Tweet 0
  • Acting CFTC Chair warns crypto firms against rule-bending under Trump Era

    0 shares
    Share 0 Tweet 0

Latest News

Foster Denovo launches tool to make advice more accessible

Foster Denovo launches tool to make advice more accessible

June 13, 2025
0

Foster Denovo has launched a digital tool MyAdvicePlace (MAP) to make financial advice more accessible to people regardless of their...

Former Blockchain Exec Joins SEC As Director Of Trading And Markets

Former Blockchain Exec Joins SEC As Director Of Trading And Markets

June 13, 2025
0

The US Securities and Exchange Commission (SEC) has announced several new hires, including those with experience in the cryptocurrency and...

Apple of his eye: Ray tries out the new Apple Car Play Ultra dashboard system

RAY MASSEY: Aston Martin helps usher in era of the ‘iDashboard’

June 13, 2025
0

Nowadays, modern cars have so much software on board they are often dubbed 'computers on wheels.'Well, brace yourself: the British luxury performance...

Damage to Iranian nuclear sites so far appears limited, experts say

Damage to Iranian nuclear sites so far appears limited, experts say

June 13, 2025
0

Damage to Iranian nuclear sites so far appears limited, experts say

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2024 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2024 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.