They’re exploiting Windows driver signing using a certificate loophole and some OS hooks to trick the date verification.