Microsoft is investigating an attack, threat actor used a driver signed by the IT giant, the Netfilter Driver, to implant a Rootkit. The actor used the malicious driver to spoof their geo-location to cheat the system and play from anywhere. Microsoft has suspended the account used to submit the driver and reviewed its submissions for additional indicators of malware. The malware allowed the attackers to gain an advantage in games and possibly take over the accounts of other players using common tools like keyloggers. Microsoft said its WHCP signing certificate was not exposed and that its infrastructure was not compromised by hackers.”]
Source: https://securityaffairs.co/wordpress/119476/malware/netfilter-driver-microsoft-attack.html