https://www.pcgamer.com/a-driver-containing-rootkit-malware-was-certified-by-microsoft/ Skip to main content (*) ( ) [] PC Gamer THE GLOBAL AUTHORITY ON PC GAMES [ ] Search [ ] Subscribe UK US Canada Australia Please deactivate your ad blocker in order to see our subscription offer * * News * Reviews * Hardware * Indie * Best Of * Magazine * Forum * Holiday * More + Podcasts + Meet the team + Newsletter Signup + Community Guidelines + Affiliate Links + About PC Gamer Popular * Windows 11 * Elden Ring * Battlefield 2042 * Starfield * E3 2021 * Witcher Season 2 PC Gamer is supported by its audience. When you buy through links on our site, we may earn an affiliate commission. Learn more 1. Home 2. News A driver containing rootkit malware was certified by Microsoft By Jody Macgregor 28 June 2021 "Microsoft is investigating a malicious actor distributing malicious drivers within gaming environments." * * * * * * Comments (Image credit: Pixabay) Microsoft tests drivers before assigning them a digital certificate that approves them to be installed by default. Somehow, a driver called Netfilter that redirects traffic to an IP in China and installs a root certificate to the registry managed to make it through that testing without being detected as malware. Karsten Hahn, a malware analyst at G Data, found the malicious driver and notified Microsoft, "who promptly added malware signatures to Windows Defender and are now conducting an internal investigation." Microsoft also suspended the account that submitted the driver, and is currently going over their previous submissions. Microsoft's security response center team described the malware's activity as "limited to the gaming sector specifically in China" and explained its purpose: "The actor's goal is to use the driver to spoof their geo-location to cheat the system and play from anywhere. The malware enables them to gain an advantage in games and possibly exploit other players by compromising their accounts through common tools like keyloggers." How did this happen? Right now, nobody knows. Windows users are advised, "There are no actions customers should take other than follow security best practices and deploy Antivirus software such as Windows Defender for Endpoint." Jody Macgregor * Jody is that guy who will try to convince you to play some indie game you've never heard of with a name like Extreme Meatpunks Forever. He is also on a doomed quest to play every Warhammer game. See comments Topics Microsoft Windows Load Comments Recommended [missing-im] Microsoft announces Windows 11 release date for the holidays, and beta builds releasing next week [missing-im] Elden Ring looks exactly like Dark Souls, but what looks better than Dark Souls? PC Gamer Newsletter Sign up to get the best content of the week, and great gaming deals, as picked by the editors. [ ] [ ] [ ] Contact me with news and offers from other Future brands [ ] Receive email from us on behalf of our trusted partners or sponsors [Sign me up] Thank you for signing up to PC Gamer. You will receive a verification email shortly. There was a problem. Please refresh the page and try again. No spam, we promise. You can unsubscribe at any time and we'll never share your details without your permission. HARDWARE BUYING GUIDESLATEST GAME REVIEWS 1. Best wireless gaming mouse 1 Best wireless gaming mouse 2. 2 The best wireless gaming keyboard in 2021 3. 3 The best CPU for gaming in 2021 4. 4 The best microphone for streaming, gaming, and podcasting 5. 5 The best gaming PC in 2021 1. Biomutant 1 Biomutant review 2. 2 Chivalry 2 review 3. 3 Dungeons & Dragons: Dark Alliance review 4. 4 Roguebook review 5. 5 Sniper Ghost Warrior Contracts 2 review PC Gamer is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site. * About Us * Terms and conditions * Privacy policy * Cookies policy * Advertise with us * Accessibility Statement (c) Future US, Inc. 11 West 42nd Street, 15th Floor, New York, NY 10036.