NetfilterRootkit

Malware type
rootkit
Profile updated
2026-07-07 13:47:21

Targeted industries: media-and-entertainment

Context

NetfilterRootkit is a WFP application layer enforcement callout driver which is signed by Microsoft via the Windows Hardware Compatibility program. It was first discovered by Karsten Hahn. His team submitted the malware to Microsoft, which allowed Microsoft to start an investigation. After Karsten Hahn published tweets and an article about the rootkit, Microsoft quickly responded with their own article. Their investigation revealed Chinese gamers as targets of the malware. The rootkit redirects traffic to the threat actor's IP. The threat actor can use the driver to spoof their geo-location to cheat, but it also allows account compromise of targeted players. While this particular rootkit is not significant anymore, similar rootkits have been created since that are also signed by Microsoft via the Windows Hardware Compatibility program.

Reports & references

  • blog.bushidotoken.net — Gamer Cheater Hacker Spy (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Netfilter (report)
  • Microsoft — Investigating And Mitigating Malicious Drivers (report)
  • blog.360totalsecurity.com — Netfilter Rootkit Ii Continues To Hold Whql Signatures (report)
  • gdatasoftware.com — Microsoft Signed A Malicious Netfilter Rootkit (report)
  • vice.com — Hackers Tricked Microsoft Into Certifying Malware That Could Spy On Users (report)
  • bitdefender.com — Bitdefender Dt Whitepaper Fivesys Creat5699 En En (report)
  • splintersfury.github.io — Netfilter Driver (report)
  • intezer.com — Fast Insights For A Microsoft Signed Netfilter Rootkit (report)

External references