Windows 10: Malware with faked timestamps on the rise to bypass Windows protections

Discus and support Malware with faked timestamps on the rise to bypass Windows protections in Windows 10 News to solve the problem; Microsoft banned more 100 signed malicious Windows drivers just last week after it was informed that malicious actors had joined the company's Windows... Discussion in 'Windows 10 News' started by GHacks, Jul 17, 2023.

  1. GHacks
    GHacks New Member

    Malware with faked timestamps on the rise to bypass Windows protections


    Microsoft banned more 100 signed malicious Windows drivers just last week after it was informed that malicious actors had joined the company's Windows Hardware Developer Program to create signed drivers with malware.

    Security researchers at Cisco Talos Intelligence have now pointed out another threat related to drivers on Windows.

    Microsoft implemented additional security in several versions of its Windows operating system to prevent the loading of malicious or problematic drivers on Windows devices. Windows Vista required kernel-mode drivers to be signed digitally with a certificate from a verified certificate authority.

    Kernel-mode drivers are loaded at an early stage, which gives them a lot of control over the system in question. The signature enforcement was a major gamechanger for Windows security.

    Windows 10 version 1607 introduced an updated driver signing policy. The main change required that developers had to submit kernel-mode drivers to get them signed by Microsoft's Developer Portal. This change was designed to limit malicious actors further and to make sure that drivers met requirements and security standards.

    Microsoft created three exceptions to the new policy, including that the new policy does not apply to a PC that was upgraded from an earlier version of Windows to Windows 10 version 1607, and that it does not apply on PCs with Secure Boot set to off.

    The third exception allows drivers to be signed with "end-entity certificate issued prior to July 29th 2015 that chains to a supported cross-signed CA"; this third exception creates a loophole, according to Cisco.

    Malicious actors have started to exploit this loophole to deploy malicious drivers without submission to Microsoft. Talos Intelligence claims that this loophole has been used to create "thousands of malicious, signed drivers" using tools that forge the signature timestamp.

    Cisco recommends to block the certificates that it mentioned in the blog post. The certificates mentioned in the blog post are the following ones:

    ???????????? (Beijing Shihai Trading Co Ltd)

    • Beijing JoinHope Image Technology Ltd.
    • Shenzhen Luyoudashi Technology Co., Ltd.
    • Jiangsu innovation safety assessment Co., Ltd.
    • Baoji zhihengtaiye co.,ltd
    • Zhuhai liancheng Technology Co., Ltd.
    • Fuqing Yuntan Network Tech Co.,Ltd.
    • Beijing Chunbai Technology Development Co., Ltd
    • ????????????
    • ?? ?
    • NHN USA Inc.
    • Open Source Developer, William Zoltan
    • Luca Marcone
    • HT Srl

    The security researchers analyzed 300 malicious samples and discovered that about half used a language code. The majority of samples with language code were set to Chinese (Simplified).

    Cisco notes that Microsoft has blocked the certificates mentioned in the blog post as a response.



    Thank you for being a Ghacks reader. The post Malware with faked timestamps on the rise to bypass Windows protections appeared first on gHacks Technology News.

    read more...
     
    GHacks, Jul 17, 2023
    #1
  2. Borg 386 Win User

    Beware this fake Windows BSOD from tech support scammers' malware

    Microsoft: Beware this fake Windows BSOD from tech support scammers' malware | ZDNet


    Malware with faked timestamps on the rise to bypass Windows protections 107379d1485973317t-beware-fake-windows-bsod-tech-support-scammers-malware-hic8.png
     
    Borg 386, Jul 17, 2023
    #2
  3. Malware Protection Live

    Just an FYI to everyone. Malware Protection Live just piggybacked an update to Windows 10 that I just received. It was accepted as an install and I just tried to delete it from the program list. it was removed from the list, but not sure of the ramification
    residue yet. However, I wish to state that it was downloaded when my Windows 10 updated just now.

    Watch out and protect yourselves.
     
    WarrenHoar, Jul 17, 2023
    #3
  4. Brink Win User

    Malware with faked timestamps on the rise to bypass Windows protections

    Windows 10: protection against recent Depriz malware attacks


    Source: Windows 10: protection, detection, and response against recent Depriz malware attacks Microsoft Malware Protection Center
     
    Brink, Jul 17, 2023
    #4
Thema:

Malware with faked timestamps on the rise to bypass Windows protections

Loading...
  1. Malware with faked timestamps on the rise to bypass Windows protections - Similar Threads - Malware faked timestamps

  2. explorer.exe fake timestamp and surveil Chinese antivirus software

    in AntiVirus, Firewalls and System Security
    explorer.exe fake timestamp and surveil Chinese antivirus software: Dear Microsoft team,I hope this message finds you well. I'm an enthusiastic and committed user of your products, but I've recently come across a concerning issue that I and others in the community would appreciate your immediate attention to.In the latest operating system...
  3. explorer.exe fake timestamp and surveil Chinese antivirus software

    in Windows 10 Gaming
    explorer.exe fake timestamp and surveil Chinese antivirus software: Dear Microsoft team,I hope this message finds you well. I'm an enthusiastic and committed user of your products, but I've recently come across a concerning issue that I and others in the community would appreciate your immediate attention to.In the latest operating system...
  4. explorer.exe fake timestamp and surveil Chinese antivirus software

    in Windows 10 Software and Apps
    explorer.exe fake timestamp and surveil Chinese antivirus software: Dear Microsoft team,I hope this message finds you well. I'm an enthusiastic and committed user of your products, but I've recently come across a concerning issue that I and others in the community would appreciate your immediate attention to.In the latest operating system...
  5. Malware protection

    in Windows 10 Gaming
    Malware protection: Which is the best antimalware program for windows 11 https://answers.microsoft.com/en-us/windows/forum/all/malware-protection/c3142fce-66ae-42e7-bd5a-5ee4a13912de
  6. Malware protection

    in Windows 10 Software and Apps
    Malware protection: Which is the best antimalware program for windows 11 https://answers.microsoft.com/en-us/windows/forum/all/malware-protection/c3142fce-66ae-42e7-bd5a-5ee4a13912de
  7. Fake malware notice(?)

    in AntiVirus, Firewalls and System Security
    Fake malware notice(?): I got this notice when I turned on my PC, i checked microsoft’s technical support phone number list and didnt see the number listed below, so im pretty sure this is fake, but how can I make sure my PC is truly safe? If i got this message how can I know for sure that I dont...
  8. FAKE AD LEADS TO MALWARE SITE

    in AntiVirus, Firewalls and System Security
    FAKE AD LEADS TO MALWARE SITE: In a Bing search, I came across an online ad which lists our company name, our web address and other info about our company. Click on the ad and you will be redirected to somewhere else. We did not place any online ads. To whom would I direct an inquiry?...
  9. Fake Microsoft malware

    in Windows 10 Software and Apps
    Fake Microsoft malware: my sister (truly) clicked on a news site that seems to have hijacked her computer. The Microsoft scam and when she didnt click on the button they called her. She cant get into her internet home page. She unplugged, restarted, etc. It boots normally and then the hacked page...
  10. Malware Protection

    in AntiVirus, Firewalls and System Security
    Malware Protection: What is the best Free Malware to download. https://answers.microsoft.com/en-us/windows/forum/all/malware-protection/020224cb-78a2-4821-9758-5a8efc88ba2e"