Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› NVIDIA Code-Signing Certificates Stolen 2022: How Lapsus$ Leaked…
Breach analysis Incident: 25 Feb 2022

NVIDIA Code-Signing Certificates Stolen 2022: How Lapsus$ Leaked Keys That Were Used to Sign Malware

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: NHI
Attack route: Not disclosed Identities: Signing key or certificate
On this page

In late February 2022, NVIDIA confirmed it was investigating a cybersecurity incident, and on 1 March it said the attacker had taken employee credentials and proprietary information. The data extortion group Lapsus$ claimed the attack, said it held 1TB of NVIDIA data and began leaking it. The leak included two code-signing certificates that NVIDIA developers had used to sign drivers and executables. Both certificates had expired, but Windows still accepted them for driver signing. Within days, researchers found malware signed with them on VirusTotal, including Cobalt Strike beacons, Mimikatz, backdoors and remote access trojans, so malicious files could pose as NVIDIA software. Revoking the certificates outright would also have broken legitimate NVIDIA drivers. Microsoft's David Weston advised administrators to use Windows Defender Application Control policies to control which NVIDIA drivers could load. NVIDIA has not said how Lapsus$ got in.

Key takeaways

  • NVIDIA said it became aware of a cybersecurity incident on 23 February 2022 and that the attacker "took employee credentials and some NVIDIA proprietary information"; Lapsus$ claimed the attack and leaked data.
  • The leak included two NVIDIA code-signing certificates used to sign drivers and executables, according to BleepingComputer; both were expired but still accepted by Windows for driver signing.
  • Malware signed with the certificates, including Cobalt Strike beacons, Mimikatz, backdoors and remote access trojans, appeared on VirusTotal soon after; ThreatDown says the first samples showed up one day after the leak.
  • The theft of the certificates is confirmed by the leak and the signed samples; NVIDIA's statements quoted in the coverage did not address them, and how Lapsus$ got into NVIDIA has not been disclosed.
  • The identity lesson: a signing key is the identity of every binary it signs, and an expired certificate is not a retired one if the platform still trusts it.

At a glance

OrganisationNVIDIA
WhenNVIDIA became aware on 23 February 2022; first reported 25 February 2022; certificates leaked and malware signed with them from early March 2022
AttackerLapsus$ data extortion group, which claimed the attack; certificate misuse by unnamed malware operators
Entry pointNot disclosed by NVIDIA
Identities abusedTwo NVIDIA code-signing certificates and their private keys; employee credentials taken in the breach
ImpactMalware signed as NVIDIA software, including Cobalt Strike, Mimikatz, backdoors, remote access trojans and a Windows driver; proprietary data leaked
CategoryNHI. Incident class: confirmed NHI breach (stolen code-signing certificates used to sign malware)

What happened

On 25 February 2022, TechCrunch reported that NVIDIA was investigating a cyber incident that, according to The Telegraph, had taken down its email and developer tools. "We are still working to evaluate the nature and scope of the event," NVIDIA said. On 1 March, NVIDIA gave BleepingComputer a fuller statement: "On February 23, 2022, NVIDIA became aware of a cybersecurity incident which impacted IT resources." It said "the threat actor took employee credentials and some NVIDIA proprietary information from our systems," and "We have no evidence of ransomware being deployed on the NVIDIA environment." By then Lapsus$ had claimed the attack, said it had 1TB of NVIDIA data, shared password hashes it said belonged to employees and leaked an archive of close to 20GB.

The certificates surfaced in that leak. "The leak includes two stolen code-signing certificates used by NVIDIA developers to sign their drivers and executables," BleepingComputer reported on 5 March. Security researcher Bill Demirkapi pointed out the problem on 3 March: "Although they have expired, Windows still allows them to be used for driver signing purposes." A code-signing certificate tells Windows and security tools who published a file. With NVIDIA's private keys, anyone could make a program or kernel driver look like NVIDIA's.

It happened quickly. Researchers including Kevin Beaumont and Will Dormann shared the certificates' serial numbers, and samples signed with them appeared on VirusTotal. BleepingComputer listed Cobalt Strike beacons, Mimikatz, backdoors, remote access trojans such as Quasar RAT and a Windows driver among them. ThreatDown by Malwarebytes wrote that "the first malware samples signed with these certificates started to show up only one day after they were leaked." It explained why the expired certificates still worked: Windows will accept expired certificates for drivers, and Secure Boot's timestamp rules had an exception for certificates created before 29 July 2015, which both leaked certificates predate.

The fix was not simple. BleepingComputer noted that adding the certificates to a revocation list would also block legitimate NVIDIA drivers signed with them. Microsoft's David Weston suggested Windows Defender Application Control instead: "Create a policy with the Wizard and then add a deny rule or allow specific versions of Nvidia if you need." ThreatDown advised downloading drivers only from NVIDIA, checking certificate validity before running installers and hunting for files signed with the leaked serial numbers. Signing does not hide malware from detection, ThreatDown added, so anti-malware tools could still catch the samples.

Timeline

DateEvent
23 February 2022NVIDIA becomes aware of a cybersecurity incident affecting IT resources.
25 February 2022NVIDIA confirms to TechCrunch that it is investigating a cyber incident.
1 March 2022NVIDIA says employee credentials and proprietary information were taken; Lapsus$ has claimed the attack and leaked data.
3 March 2022Bill Demirkapi flags two leaked NVIDIA code-signing certificates still usable for driver signing.
5 March 2022BleepingComputer reports malware signed with the certificates on VirusTotal.
14 March 2022ThreatDown by Malwarebytes publishes detection and mitigation advice.

How it happened: the identity attack path

  1. Network intrusion. Lapsus$ got into NVIDIA's environment by a route NVIDIA has not disclosed and took employee credentials and proprietary data.
  2. Signing material taken. The stolen data included two code-signing certificates with their private keys, used by NVIDIA developers to sign drivers and executables.
  3. Public leak. Lapsus$ published the data, putting the signing keys within reach of anyone who downloaded it.
  4. Malware signed as NVIDIA. Others used the keys to sign Cobalt Strike beacons, Mimikatz, backdoors, remote access trojans and a driver, which Windows accepted despite the certificates' expiry.
  5. Limited revocation options. Because legitimate drivers depended on the same certificates, defenders were pointed to application control policies rather than a clean revocation.

Impact

  • Confirmed: two NVIDIA code-signing certificates leaked and used to sign malware found on VirusTotal; employee credentials and proprietary information taken, according to NVIDIA.
  • Claimed: Lapsus$ said it took 1TB of data and shared password hashes it said belonged to NVIDIA employees.
  • Business: NVIDIA said it had no evidence of ransomware in its environment and did not expect disruption to its business.
  • Potential: signed malicious drivers can load into the Windows kernel and signed tools can pass checks that trust the publisher, giving attackers a way past controls that rely on signatures.

What this means for NHI governance

A code-signing certificate is a machine identity. It does not log in anywhere, but it vouches for software on millions of machines, and its private key is the credential. When NVIDIA's keys leaked, the identity they represented became available to anyone, and the fact that the certificates had expired did not help, because Windows kept trusting them for drivers. The same lesson came out of the GitHub code signing certificate theft later in 2022 and the MSI signing keys leak in 2023.

Signing keys that sit in files can be copied in any breach that reaches the right share or repository. Keeping them in hardware security modules or a managed signing service, limiting who and what can request a signature, and logging every signing operation turn a leaked file into a non-event. Planning ahead for revocation matters too: the harder it is to revoke a certificate without breaking customers, the longer a stolen one stays useful. Our Machine Identity, PKI and Certificate Lifecycle Guide and Cryptographic Key Management Guide cover these controls.

Recommendations

  • Keep code-signing keys in hardware. Store private keys in an HSM or managed signing service so they cannot be copied out with a file share or repository. See our Cryptographic Key Management Guide.
  • Control and log every signing request. Allow only approved build pipelines to request signatures and review the signing log for anything that did not come from a release.
  • Plan for revocation before you need it. Use separate certificates for separate products and timestamp signatures so a compromised certificate can be revoked without breaking every past release. See our Machine Identity, PKI and Certificate Lifecycle Guide.
  • Block leaked certificates with application control. As Microsoft advised, use WDAC or similar policies to deny binaries and drivers signed with known stolen certificates.
  • Hunt for files signed with leaked serial numbers. Add the serial numbers of publicly leaked certificates to endpoint detection and file scanning rules.
  • Treat a source code leak as a key leak. After any breach of development systems, inventory and rotate signing keys and other secrets the attacker could have reached. See the Leaked Credential Response Playbook.

Frequently asked questions

What happened to NVIDIA's code-signing certificates?

Two NVIDIA code-signing certificates were stolen in the February 2022 breach claimed by Lapsus$ and published in the group's leak. Within days, attackers used them to sign malware, including Cobalt Strike beacons and Mimikatz, so the files appeared to come from NVIDIA.

Why could expired NVIDIA certificates still sign malware?

Windows still accepts expired certificates for driver signing, and Secure Boot's timestamp rules had an exception for certificates created before 29 July 2015, which both leaked certificates predate. Revoking them would also have blocked legitimate NVIDIA drivers.

How can organisations protect against malware signed with stolen certificates?

Microsoft advised using Windows Defender Application Control policies to deny or tightly allow NVIDIA drivers. Security teams can also hunt for files signed with the leaked serial numbers and should download drivers only from the vendor.

GitHub Code Signing Certificate Theft 2022 · Samsung Source Code Leak 2022 · MSI Signing Keys Leak 2023 · Machine Identity, PKI and Certificate Lifecycle Guide · Cryptographic Key Management Guide

How NHI Mgmt Group can help

Signing keys and certificates are machine identities that rarely get the attention of user accounts. We help teams find where their signing keys live, move them into hardware-backed services and prepare revocation plans before a leak forces one. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org