This article has been indexed from Security Blog G Data Software AG
What started as a false positive alert for a Microsoft signed file turns out to be a WFP application layer enforcement callout driver that redirects traffic to a Chinese IP. How did this happen?
Read the original article: Microsoft signed a malicious Netfilter rootkit