Tag: EDRs operating

Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
News

Akira ransomware abuses CPU tuning tool to disable Microsoft Defender

In attacks from security tools and EDRs operating on target computers, the Akira ransomware disables Microsoft Defender by misusing a genuine Intel CPU tuning driver. Threat actors register the misused driver, 'rwdrv.sys' (used by ThrottleStop), as a service in order to obtain kernel-level access. 'hlpdrv.sys,' a malicious malware that manipulates Windows Defender to disable its defenses, is probably loaded by this driver. This is an example of a "Bring Your Own Vulnerable Driver" (BYOVD) attack, in which threat actors utilize authentic signed drivers with known flaws or vulnerabilities that could be exploited to escalate privileges. A malicious tool that disables Microsoft Defender is then loaded using this driver read more about Akira ransomware abuses CPU tuning tool to disabl...