Aryeh Goretsky
Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades.
Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee.
Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.
[UPDATE 20260503-2020 UTC: Clarified type of certificate involved since it appears there may be two unrelated certificate revocations that were conflated as one event. ^AG]
This is an evolving situation, but it appears that a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate issued by #DigiCert was stolen by a threat actor for misuse.
#Microsoft is now detecting the stolen code-signing certificate as "Trojan:Win32/Cerdigent.A!dha" via Microsoft Windows Defender, with a not-yet-very-detailed entry about it at:
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Cerdigent.A!dha&ThreatID=2147968144
Computer security researcher @cyb3rops@infosec.exchange has a discussion about it on Twitter at:
https://x.com/cyb3rops/status/2050916842730869197
as well as the following update:
https://x.com/cyb3rops/status/2050924042173943820
This discussion may or may not be related to the 𝗿𝗼𝗼𝘁 certificate issue. It discusses stolen code-signing certificates:
T̶h̶e̶r̶e̶'̶s̶ ̶a̶ ̶s̶o̶m̶e̶w̶h̶a̶t̶ ̶t̶e̶c̶h̶n̶i̶c̶a̶l̶ ̶d̶i̶s̶c̶u̶s̶s̶i̶o̶n̶ ̶o̶f̶ ̶t̶h̶e̶ ̶t̶h̶e̶f̶t̶ ̶i̶n̶ ̶M̶o̶z̶i̶l̶l̶a̶'̶s̶ ̶b̶u̶g̶ ̶d̶a̶t̶a̶b̶a̶s̶e̶ ̶a̶s̶ ̶w̶e̶l̶l̶:̶
https://bugzilla.mozilla.org/show_bug.cgi?id=2033170
There's also an ongoing discussion on Reddit about it as well at:
https://old.reddit.com/r/antivirus/comments/1t2l6tk/windows_defender_picked_up_a_trojan_what_do_i_do/
At this point, there's not really a lot for most Windows users to do here. This is, or at least was, a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate, so its presence on a system is not unexpected. And just because it was found on a system does not mean the system has malware on it or was targeted by a threat actor.
I recommend monitoring the situation and wait for additional clarification from Microsoft.
Hello @Judeau@mas.to, It is hard to say what happened without an explanation from the company, but in the past shipping infected media and even computers was usually the result of a number of things:
-
Old and/or obsolete computers were used during the manufacturing process, and these had no modern protections that newer OSes have, including running up-to-date antivirus software.
-
Use of pirated operating systems or software during the manufacturing process to cut operating costs.
-
Improper security controls on the manufacturing line. The computers used to make the devices might not have been dedicated to just manufacturing and have been used for other things (web browsing, email, downloading and running random software, and so on).
Any of these, or a combination of them could have led to the company shipping malware. However, I'll also note that unless they have an investigation and share it, this all remains hypothetical and we'll likely never know the source.