Hackers are using Stolen Nvidia certificates to authenticate malware

Hackers that broke into Nvidia’s network disclosed a stockpile of stolen data, including genuine code-signing certificates presently being exploited in the wild. Several security experts have obtained instances of suspicious software payloads that leverage at least two of Nvidia’s digital certificates, according to reports. In a tweet on Friday, threat expert Mehmet Ergene detected many malicious files signed with one of the Nvidia certificates.

The certificates were purportedly provided as a current data payload by criminal hackers linked to the Lapsus$ ransomware group. The organisation claimed to have gained access to Nvidia’s business network and a large internal data cache.

Even though one of the security certificates is old, dating back to 2014, it is still valid for Windows systems. As a result, attackers can utilise the certificate to make their malware payloads appear legitimate AMD software updates.

Nvidia has yet to reply to a request for comment on the certificates’ publication. Although researchers have released Yara rules that administrators may employ to detect and stop malicious downloads, many end users may still be vulnerable to malware payloads masquerading as Nvidia graphics card firmware or software upgrades.

“On February 23, 2022, NVIDIA became aware of a cybersecurity incident which impacted IT resources,” Nvidia said in a statement earlier this week. “Shortly after discovering the incident, we further hardened our network, engaged cybersecurity incident response experts, and notified law enforcement.”

Nvidia
NVIDIA certificates used to sign malware, Source: Florian Roth

Hackers are using Stolen Nvidia certificates to authenticate malware

Nvidia has stated that the network intrusion had no impact on its day-to-day operations and did not expect it to alter. Meanwhile, the Lapsus$ hackers have threatened to expose more Nvidia material, including technical insights about future GPU designs and graphics card platforms.

The group’s primary demand is that Nvidia releases its graphics card drivers as open-source projects, which would allow developers to optimise the hardware better and add new features.

Nvidia
NVIDIA certificates used to sign malware, Source: Florian Roth

The hacker group specifically requests that Nvidia eliminate its Lite Hash Rate (LHR) limits, limiting GPUs’ ability to compute the equations required to mine cryptocurrencies. Nvidia used LHR to reduce the gaming sector’s mining purchases of graphics cards, which resulted in a vast product shortage.

Also Read:

NVIDIA hackers have now targeted Samsung in their latest heist

Source

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More like this

NVIDIA AI PC SoC

NVIDIA Shatters Records: $39.3 Billion Q4 Revenue & AI...

NVIDIA has once again outperformed expectations, reporting a record-breaking Q4 revenue of $39.3 billion, marking a 12%...
NVIDIA GeForce RTX 5070 Benchmarks Leak: A 20% Boost Over RTX 4070

NVIDIA GeForce RTX 5070 Benchmarks Leak: A 20% Boost...

The wait is over! NVIDIA’s GeForce RTX 5070 benchmarks have surfaced, revealing an impressive 20% performance boost...
AMD & Intel Gain GPU Market Share in Korea as NVIDIA Struggles with Availability

AMD & Intel Gain GPU Market Share in Korea...

The GPU landscape is shifting in 2025, and for once, it's not NVIDIA dominating the charts. AMD...
NVIDIA GeForce RTX 5050, 5060, and 5070 GPUs Spotted: Affordable Powerhouses Coming Soon?

NVIDIA GeForce RTX 5050, 5060, and 5070 GPUs Spotted:...

The GPU market is heating up once again as NVIDIA's next-generation GeForce RTX 50 series, including the...
NVIDIA GeForce RTX 5070: A New Contender in the GPU Market, Launching Alongside AMD's RX 9070 Series

NVIDIA GeForce RTX 5070: Launching Alongside AMD’s RX 9070...

The GPU market is about to heat up. As of early February 2025, new rumors surrounding NVIDIA’s...

LATEST NEWS

Viduthalai Part 2 OTT Release Date: Stream the Soori-Vijay Sethupathi Thriller Online Soon

Vetrimaaran's eagerly awaited sequel, Viduthalai Part 2, has finally arrived in theatres, mesmerizing audiences with its compelling narrative and standout performances. Featuring the talents...

Sorgavaasal: RJ Balaji’s Prison Thriller Set for OTT Release on Netflix

After capturing hearts in theatres, RJ Balaji's gripping Tamil prison break thriller Sorgavaasal is ready to make its digital debut. Directed by the promising...

Fateh OTT Release Date: When Will Sonu Sood’s Action-Packed Thriller Stream Online?

Sonu Sood steps behind the camera for his directorial debut Fateh, making a bold entrance into the 2025 Hindi cinema landscape. Since its theatrical...

Tamannaah Bhatia Is Spreading Fire on the Internet In Stylish Black Saree

In the grand theater of Bollywood fashion, some moments transcend mere clothing – they become cultural statements. The Recent look of Tamannaah Bhatia in...

Featured