How strange, shouldn't windows be checking if the binary is signed? Isn't that part of what secureboot and deviceguard do? Or does it just run like any addon?
Besides manipulating executables, the adversary could simply modify or read the user database in C:\Windows\System32\config\SAM. [1]
Alternatively, patch routines directly in memory [2]
Linux can be setup to verify an immutable userland via secure boot + dm-verity. I think it's used in some google devices (chromebooks?).
First set of changes already in flight for the next Windows 11 stable release.