Hackers Exploit Windows Loopholes for Malware and Browser Hijacking

1 min read
Source: Ars Technica
Hackers Exploit Windows Loopholes for Malware and Browser Hijacking
Photo: Ars Technica
TL;DR Summary

Hackers are utilizing open source software popular among video game cheaters to bypass Microsoft's restrictions on Windows-based malware. The software tools, HookSignTool and FuckCertVerifyTimeValidity, are being repurposed by Chinese-speaking threat groups to give their malware kernel access. These tools allow the threat actors to digitally sign malicious system drivers, granting them capabilities they wouldn't otherwise have. The technique exploits a loophole in Windows driver restrictions that allows older drivers, signed by a trusted certificate authority prior to July 29, 2015, to bypass safety reviews by Microsoft. This poses a serious threat to Windows systems and is relatively easy to perform due to the availability of the tools.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

3 min

vs 4 min read

Condensed

83%

620107 words

Want the full story? Read the original article

Read on Ars Technica