Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
In attacks from security tools and EDRs operating on target computers, the Akira ransomware disables Microsoft Defender by misusing a genuine Intel CPU tuning driver.
Threat actors register the misused driver, 'rwdrv.sys' (used by ThrottleStop), as a service in order to obtain kernel-level access.
'hlpdrv.sys,' a malicious malware that manipulates Windows Defender to disable its defenses, is probably loaded by this driver.
This is an example of a "Bring Your Own Vulnerable Driver" (BYOVD) attack, in which threat actors utilize authentic signed drivers with known flaws or vulnerabilities that could be exploited to escalate privileges. A malicious tool that disables Microsoft Defender is then loaded using this driver read more about Akira ransomware abuses CPU tuning tool to disabl...

