FortiGuard Labs is aware that Microsoft recently disclosed that threat actors had used Windows drivers certified by Microsoft maliciously, which prompted them to revoke their signing certificates. According to the Microsoft’s advisory, the malicious drivers were used for post-exploitation activities including ransomware deployment to compromised machines. Separate reports indicate malicious signed-driver named “POORTRY” and STONESTOP malware was used to terminate processes belonging to AV and EDR solutions. Why is this Significant?This is significant because malicious drivers legitimately signed by Microsoft are trusted by the operating system and the use of such drivers allows attackers to perform activities with highest privileges on compromised machines. One of the reported activities include the deployment of Cuba ransomware. Other reports indicate threat actors used “POORTRY”, a malicious driver signed by Microsoft, and STONESTOP malware to terminate processes belonging to AV and EDR solutions.Microsoft’s advisory states that they suspended developer accounts that were likely abused by threat actors to get Microsoft to sign malicious files through a legitimate process. Also, Microsoft revoked signing certificates used to sign the malicious files.What is the Status of Coverage?FortiGuard Labs provides the following AV signatures for the reported and available samples involved in the incident:W64/BURNTCIGAR.BQ!trW64/BURNTCIGAR.CA!trW64/BURNTCIGAR.CB!trW64/Agent.ARD!trRiskware/BURNTCIGARW32/PossibleThreat
More Stories
chromium-135.0.7049.84-1.fc42
FEDORA-2025-0f2d318242 Packages in this update: chromium-135.0.7049.84-1.fc42 Update description: Update to 135.0.7049.84 CVE-2025-3066: Use after free in Site Isolation Read More
python-uv-build-0.6.14-2.fc43 rust-gitui-0.26.3-6.fc43 rust-gstreamer-0.23.5-2.fc43 rust-ron-0.9.0-1.fc43 rust-version-ranges-0.1.1-2.fc43 rust-zip-2.6.1-1.fc43 uv-0.6.14-3.fc43
FEDORA-2025-1311e4cd58 Packages in this update: python-uv-build-0.6.14-2.fc43 rust-gitui-0.26.3-6.fc43 rust-gstreamer-0.23.5-2.fc43 rust-ron-0.9.0-1.fc43 rust-version-ranges-0.1.1-2.fc43 rust-zip-2.6.1-1.fc43 uv-0.6.14-3.fc43 Update description: Update rust-ron to 0.9. Update rust-zip...
rpki-client-9.5-1.el10_0
FEDORA-EPEL-2025-2ec16b3a94 Packages in this update: rpki-client-9.5-1.el10_0 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.fc41
FEDORA-2025-17fed14cc3 Packages in this update: rpki-client-9.5-1.fc41 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.fc40
FEDORA-2025-d5fdbedb7f Packages in this update: rpki-client-9.5-1.fc40 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.el9
FEDORA-EPEL-2025-f8a9a83d41 Packages in this update: rpki-client-9.5-1.el9 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....