NVIDIA’s Code Signing Certificates Stolen and Abused in Attacks
Lapsus$, responsible for the recent attack on Nvidia, reportedly released two of the company’s old code-signing certificates, and threat actors have started abusing it. In some cases, the stolen certificates were used to sign Cobalt Strike beacons, Mimikatz, backdoors, and remote access trojans. Admins are suggested to configure Windows Defender Application Control policies to control NVIDIA drivers loaded into Windows OS.