Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.
Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades.
Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee.
Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.
Posts
Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.
Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.
Security researcher and antivirus pioneer who's been at the intersection of security research, education, and community for over three decades. Formerly the Distinguished Researcher at #ESET, and first employee at #McAfee. Moderator at the Lenovo, Neowin, and Scots Newsletter forums, and Intel Insider Council member. 14× Microsoft MVP award recipient.
[UPDATE 20260503-2020 UTC: Clarified type of certificate involved since it appears there may be two unrelated certificate revocations that were conflated as one event. ^AG]
This is an evolving situation, but it appears that a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate issued by #DigiCert was stolen by a threat actor for misuse.
#Microsoft is now detecting the stolen code-signing certificate as "Trojan:Win32/Cerdigent.A!dha" via Microsoft Windows Defender, with a not-yet-very-detailed entry about it at:
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Cerdigent.A!dha&ThreatID=2147968144
Computer security researcher @cyb3rops@infosec.exchange has a discussion about it on Twitter at:
https://x.com/cyb3rops/status/2050916842730869197
as well as the following update:
https://x.com/cyb3rops/status/2050924042173943820
This discussion may or may not be related to the 𝗿𝗼𝗼𝘁 certificate issue. It discusses stolen code-signing certificates:
T̶h̶e̶r̶e̶'̶s̶ ̶a̶ ̶s̶o̶m̶e̶w̶h̶a̶t̶ ̶t̶e̶c̶h̶n̶i̶c̶a̶l̶ ̶d̶i̶s̶c̶u̶s̶s̶i̶o̶n̶ ̶o̶f̶ ̶t̶h̶e̶ ̶t̶h̶e̶f̶t̶ ̶i̶n̶ ̶M̶o̶z̶i̶l̶l̶a̶'̶s̶ ̶b̶u̶g̶ ̶d̶a̶t̶a̶b̶a̶s̶e̶ ̶a̶s̶ ̶w̶e̶l̶l̶:̶
https://bugzilla.mozilla.org/show_bug.cgi?id=2033170
There's also an ongoing discussion on Reddit about it as well at:
https://old.reddit.com/r/antivirus/comments/1t2l6tk/windows_defender_picked_up_a_trojan_what_do_i_do/
At this point, there's not really a lot for most Windows users to do here. This is, or at least was, a legitimate 𝗿𝗼𝗼𝘁 c̶o̶d̶e̶-̶s̶i̶g̶n̶i̶n̶g̶ certificate, so its presence on a system is not unexpected. And just because it was found on a system does not mean the system has malware on it or was targeted by a threat actor.
I recommend monitoring the situation and wait for additional clarification from Microsoft.