Hackers Exploit Windows Loopholes for Malware and Browser Hijacking

Hackers are utilizing open source software popular among video game cheaters to bypass Microsoft's restrictions on Windows-based malware. The software tools, HookSignTool and FuckCertVerifyTimeValidity, are being repurposed by Chinese-speaking threat groups to give their malware kernel access. These tools allow the threat actors to digitally sign malicious system drivers, granting them capabilities they wouldn't otherwise have. The technique exploits a loophole in Windows driver restrictions that allows older drivers, signed by a trusted certificate authority prior to July 29, 2015, to bypass safety reviews by Microsoft. This poses a serious threat to Windows systems and is relatively easy to perform due to the availability of the tools.
- Hackers exploit gaping Windows loophole to give their malware kernel access Ars Technica
- Hackers Exploit Windows Policy Loophole to Forge Kernel-Mode Driver Signatures The Hacker News
- Hackers target Chinese-speaking Microsoft users with 'RedDriver' browser hijacker The Record from Recorded Future News
- Hackers exploit Windows policy to load malicious kernel drivers BleepingComputer
- Hackers exploit Windows driver signature enforcement loophole for malware persistence CSO Online
Reading Insights
0
10
3 min
vs 4 min read
83%
620 → 107 words
Want the full story? Read the original article
Read on Ars Technica