PCWorld (USA)

Stolen Nvidia certificat­es used to hide malware in driver downloads

Nvidia Geforce graphics card owners may be vulnerable to malware if they’re not careful with their next driver installati­on.

- BY MICHAEL CRIDER

Last week Nvidia confirmed that it had been the victim of an internal hack, though it claimed no customer informatio­n was compromise­d. While the hackers have made some very strange demands, threatenin­g to release sensitive corporate data if Nvidia doesn’t unlock some of its most powerful graphics cards for cryptocurr­ency mining ( fave.co/3iv9ou1), regular users didn’t need to worry much. Today we’re seeing one of the first effects of the hack on end users: Nvidia GPU driver packages with malware hidden inside.

While it was always possible for malefactor­s to host links pretending to be drivers in the hopes of installing viruses, Trojans, and other nasty stuff on a user’s PC, this situation is more concerning. The hackers appear to have leaked Nvidia’s official code-signing certificat­es, a means by which users (and Microsoft) can verify that a downloaded program comes from the publisher it says it’s from.

That’s allowing files containing a host of popular malware suites to be posted and downloaded, bypassing Windows Defender’s

built-in executable verificati­on and slipping past antivirus software. Bleepingco­mputer reports that two now-expired (but still usable) verificati­on codes have been compromise­d and used to deliver remote access Trojans ( fave.co/3uijotm). Another example, using the Nvidia verificati­on to sign a fake Windows driver, was also spotted.

While it’s possible to block the installati­on of packages with the expired codes using Windows Defender, it’s an advanced technique that’s probably only of interest to your company’s sysadmin ( fave.co/3nb1bqc). For regular users looking for the latest graphics card drivers (or any driver, for that matter), the advice is the same as always: Be careful to only download it from the official source—the Nvidia website ( fave. co/3qnnwf2) or, in this case, your installati­on of Geforce Experience.

 ?? ??
 ?? ?? You can block the installati­on of packages with the expired codes using Windows Defender.
You can block the installati­on of packages with the expired codes using Windows Defender.
 ?? ?? Make sure you only download drivers from official sources.
Make sure you only download drivers from official sources.

Newspapers in English

Newspapers from Australia