Stolen Nvidia certificates used to hide malware in driver downloads

Last week Nvidia confirmed that it had been the victim of an internal hack, though it claimed no customer information was compromised. While the hackers have made some very strange demands, threatening to release sensitive corporate data if Nvidia doesn’t unlock some of its most powerful graphics cards for cryptocurrency mining, regular users didn’t need to worry much. Today we’re seeing one of the first effects of the hack on end-users: Nvidia GPU driver packages with malware hidden inside.

While it was always possible for malefactors to host links pretending to be drivers in the hopes of installing viruses, trojans, and other nasty stuff on a user’s PC, this situation is more concerning. The hackers appear to have leaked Nvidia’s official code signing certificates, a means by which users (and Microsoft) can verify that a downloaded program comes from the publisher it says it’s from.

That’s allowing files containing a host of popular malware suites to be posted and downloaded, bypassing Windows Defender’s built-in executable verification and slipping past anti-virus software. BleepingComputer reports that two now-expired (but still usable) verification codes have been compromised and used to deliver remote access trojans. Another example, using the Nvidia verification to sign a fake Windows driver, was also spotted.

While it’s possible to block the installation of packages with the expired codes using Windows Defender, it’s an advanced technique that’s probably only of interest to your company’s sysadmin. For regular users looking for the latest graphics card drivers (or any driver, for that matter), the advice is the same as always: be careful to only download it from the official source—the Nvidia website or your installation of GeForce Experience, in this case. https://www.pcworld.com/article/620181/hackers-use-stolen-nvidia-certificates-to-hide-malware-in-driver-downloads.html

Creată 3y | 7 mar. 2022, 16:20:40


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

Windows 7 took ages to load if you had a solid background. Now we know why
3 mai 2025, 17:10:11 | pcworld.com
USB flash drives are going extinct. Use these faster alternatives instead
3 mai 2025, 12:30:03 | pcworld.com
Grocery prices may be insane, but this can help you save 25%
3 mai 2025, 10:10:05 | pcworld.com
Roku to acquire the budget streaming service Frndly TV
2 mai 2025, 17:50:07 | pcworld.com
Is Netflix’s cheaper ad plan worth it? We break it down
2 mai 2025, 17:50:06 | pcworld.com
I saw how an “evil” AI chatbot finds vulnerabilities. It’s as scary as you think
2 mai 2025, 15:30:11 | pcworld.com
Why you shouldn’t waste your money on a membrane keyboard
2 mai 2025, 15:30:11 | pcworld.com