{"id":646037,"date":"2026-05-03T23:43:20","date_gmt":"2026-05-03T23:43:20","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/646037\/"},"modified":"2026-05-03T23:43:20","modified_gmt":"2026-05-03T23:43:20","slug":"microsoft-defender-wrongly-flags-digicert-certs-as-trojanwin32-cerdigent-adha","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/646037\/","title":{"rendered":"Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32\/Cerdigent.A!dha"},"content":{"rendered":"<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" alt=\"Microsoft\" height=\"900\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/microsoft-red-header.jpg\" width=\"1600\"\/><\/p>\n<p>Microsoft Defender is detecting legitimate DigiCert root certificates as Trojan:Win32\/Cerdigent.A!dha, resulting in widespread false-positive alerts, and in some cases,\u00a0removing\u00a0certificates from Windows.<\/p>\n<p>According to cybersecurity expert <a href=\"https:\/\/x.com\/cyb3rops\/status\/2050916842730869197\" target=\"_blank\" rel=\"nofollow noopener\">Florian Roth<\/a>, the issue first appeared after Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Trojan:Win32\/Cerdigent.A!dha&amp;ThreatID=2147968144\" target=\"_blank\" rel=\"nofollow noopener\">added the detections<\/a> to a Defender signature update on April 30th.<\/p>\n<p>Today, administrators worldwide <a href=\"https:\/\/www.reddit.com\/r\/cybersecurity\/comments\/1t2hfsh\/mde_flagging_digi_cert_certificate_as_malicious\/\" target=\"_blank\" rel=\"nofollow noopener\">began reporting<\/a> that DigiCert root certificate entries were flagged as malware and, on affected systems, removed from the Windows trust store.<\/p>\n<p>According to a <a href=\"https:\/\/www.reddit.com\/r\/cybersecurity\/comments\/1t2hfsh\/mde_flagging_digi_cert_certificate_as_malicious\/\" target=\"_blank\" rel=\"nofollow noopener\">Reddit post<\/a> about the false positives, the detected certificates are:<\/p>\n<p>0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43&#13;<br \/>\n\tDDFB16CD4931C973A2037D3FC83A4D7D775D05E4&#13;<\/p>\n<p>On impacted systems, these certificates were removed from the AuthRoot store under this Registry key:<\/p>\n<p>&#13;<br \/>\nHKLM\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\<\/p>\n<p>These false positives have led to concern among Windows users, with some thinking their devices were infected and reinstalling the operating system to be safe.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Microsoft Defender \" trojan:win32=\"\" false=\"\" positive=\"\" height=\"400\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/cerdigent-false-positive.jpg\" width=\"562\"\/>Microsoft Defender &#8220;Trojan:Win32\/Cerdigent.A!dha&#8221; False Positive<br \/>Source: <a href=\"https:\/\/www.reddit.com\/r\/DefenderATP\/comments\/1t2iljt\/comment\/ojo4nl7\/\" target=\"_blank\" rel=\"nofollow noopener\">Reddit<\/a><\/p>\n<p>Microsoft has reportedly fixed the detections in Security Intelligence update version 1.449.430.0, and the most recent update is now 1.449.431.0.<\/p>\n<p>Other reports on <a href=\"https:\/\/www.reddit.com\/r\/cybersecurity\/comments\/1t2ifv7\/trojanwin32cerdigentadha\/\" target=\"_blank\" rel=\"nofollow noopener\">Reddit<\/a> indicate that the fix also restores previously removed certificates on affected systems.<\/p>\n<p>The new Microsoft Defender updates will automatically install, and Windows users can manually\u00a0force an update by going into Windows Security &gt; Virus and threat protection &gt; Protection updates and clicking on Check for Updates.<\/p>\n<p>Possibly linked to a recent DigiCert breach<\/p>\n<p>The false positives occur shortly after a disclosed <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=2033170\" target=\"_blank\" rel=\"nofollow noopener\">DigiCert security incident<\/a> that enabled threat actors to obtain valid code-signing certificates used to sign malware.<\/p>\n<p>&#8220;A malware incident targeted a customer support team member. Upon detection, the threat vector was contained,&#8221; explains the DigiCert incident report.<\/p>\n<p>&#8220;Our subsequent investigation found that the threat actor was able to procure initialization codes for a limited number of code signing certificates, few of which were then used to sign malware.&#8221;<\/p>\n<p>&#8220;The identified certificates were revoked within 24 hours of discovery and the revocation date set to their date of issuance. As a precautionary measure, pending orders within the window of interest were cancelled. Additional details will be provided in our full incident report.&#8221;<\/p>\n<p>According to DigiCert&#8217;s incident report, attackers targeted the company&#8217;s support staff in early April by creating support messages containing a malicious ZIP file disguised as a screenshot.<\/p>\n<p>After multiple blocked attempts, one support analyst&#8217;s device was eventually compromised, followed by a second system that went undetected for a time due to an endpoint protection &#8220;sensor gap.&#8221;<\/p>\n<p>Using access to the breached support environment, the hacker used a feature in DigiCert&#8217;s internal support portal that allowed support staff to\u00a0view customer accounts from the customer&#8217;s perspective.<\/p>\n<p>While limited in scope, this access exposed &#8220;initialization codes&#8221;\u00a0to previously approved, but undelivered, EV code-signing certificate orders.<\/p>\n<p>&#8220;Possession of an initialization code, combined with an approved order, is sufficient to obtain the resulting certificate (see Contributing Factors discussion below),&#8221; explained DigiCert.<\/p>\n<p>&#8220;Since the threat actor was able to obtain these two pieces of information for a finite set of approved orders, they were able to obtain EV Code Signing certificates across a set of customer accounts and CAs.&#8221;<\/p>\n<p>DigiCert says it revoked 60 code-signing certificates, including 27 linked to a &#8220;Zhong Stealer&#8221; malware campaign.<\/p>\n<p>&#8220;11 were identified in certificate problem reports provided to DigiCert by community members linking the certificates to malware, and 16 were identified during our own investigation,&#8221; explained DigiCert.<\/p>\n<p>Zhong Stealer malware campaign<\/p>\n<p>This aligns with earlier reports from security researchers who had observed newly issued DigiCert EV certificates used in malware campaigns and reported them to DigiCert.<\/p>\n<p>Researchers, including <a href=\"https:\/\/x.com\/SquiblydooBlog\" target=\"_blank\" rel=\"nofollow noopener\">Squiblydoo<\/a>, <a href=\"https:\/\/x.com\/malwrhunterteam\" target=\"_blank\" rel=\"nofollow noopener\">MalwareHunterTeam<\/a>, and <a href=\"https:\/\/x.com\/g0njxa\" target=\"_blank\" rel=\"nofollow noopener\">g0njxa<\/a>, reported that certificates issued to well-known companies such as Lenovo, Kingston, Shuttle Inc, and Palit Microsystems were being used to sign malware.<\/p>\n<p>&#8220;What do Lenovo, Kingston, Shuttle Inc, and Palit Microsystems have in common?,&#8221; <a href=\"https:\/\/x.com\/SquiblydooBlog\/status\/2046190826791870739\" target=\"_blank\" rel=\"nofollow noopener\">posted\u00a0Squiblydoo on X<\/a>.<\/p>\n<p>&#8220;EV Certificates from these companies were issued and used by a Chinese crime group, #GoldenEyeDog (#APT-Q-27)!&#8221;<\/p>\n<p>The malware in this campaign is named &#8220;Zhong Stealer,&#8221;\u00a0though analysis indicates it may be more like a remote access trojan (RAT) than an infostealer.<\/p>\n<p>The researcher says the malware was distributed through the following attacks:<\/p>\n<p>Phishing emails deliver a fake image or screenshot&#13;<br \/>\n\tA first-stage executable that displays a decoy image&#13;<br \/>\n\tRetrieval of a second-stage payload from cloud storage such as AWS&#13;<br \/>\n\tUse of signed binaries and loaders, including components tied to legitimate vendors&#13;<\/p>\n<p>After DigiCert disclosed the incident, the researchers said the incident report explains how the certificates used in these malware campaigns were obtained.<\/p>\n<p>While Microsoft has not confirmed that the Defender detections are a result of the DigiCert incident, the timing and focus on DigiCert-related certificates suggest a possible connection.<\/p>\n<p>However, it should be noted that the certificates flagged by Microsoft Defender are root certificates in the Windows trust store and do not match the revoked DigiCert code-signing certificates used to sign malware.<\/p>\n<p>BleepingComputer contacted Microsoft with questions about the campaign, including whether it was tied to DigiCert&#8217;s breach.<\/p>\n<p>        <a href=\"https:\/\/hubs.li\/Q04crVgD0\" target=\"_blank\" rel=\"noopener nofollow\"><br \/>\n            <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/autonomous-validation2.jpg\" alt=\"article image\"\/><\/a><\/p>\n<p>AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.<\/p>\n<p>At the Autonomous Validation Summit (May 12 &amp; 14), see how autonomous, context-rich validation finds what&#8217;s exploitable, proves controls hold, and closes the remediation loop.<\/p>\n<p>        <a class=\"article-link\" href=\"https:\/\/hubs.li\/Q04crVgD0\" target=\"_blank\" rel=\"noopener nofollow\">Claim Your Spot<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft Defender is detecting legitimate DigiCert root certificates as Trojan:Win32\/Cerdigent.A!dha, resulting in widespread false-positive alerts, and in some&hellip;\n","protected":false},"author":2,"featured_media":646038,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,61],"class_list":["post-646037","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/646037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=646037"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/646037\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/646038"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=646037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=646037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=646037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}