Tag: vulnerable drivers

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
News

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

According to research from Cisco Talos and Trend Micro, threat actors connected to the Qilin and Warlock ransomware operations have been seen exploiting the bring your own vulnerable driver (BYOVD) approach to mute security solutions operating on affected computers. Talos' analysis of Qilin attacks revealed that they use a malicious DLL called "msimg32.dll," which starts a multi-stage infection chain to disable endpoint detection and response (EDR) systems. More than 300 EDR drivers from practically every security vendor on the market can be terminated by the DLL when it is activated via DLL side-loading. According to Talos researchers Takahiro Takeda and Holger Unterbrink, the first stage consists of a PE loader that sets up the execution environment for the EDR killer component. T...
54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security
News

54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security

According to a recent study on endpoint detection and response (EDR) killers, 54 of them abuse a total of 35 vulnerable drivers by adopting a technique called bring your own vulnerable driver (BYOVD). Since EDR killer programs allow affiliates to disable security software before to the deployment of file-encrypting malware, they have been frequently found in ransomware intrusions. This is done in an effort to avoid being discovered. According to a report shared with The Hacker News by ESET researcher Jakub Souček, ransomware gangs, particularly those with ransomware-as-a-service (RaaS) programs, regularly create new builds of their encryptors, and making sure that each new build is consistently undetected might take time. More significantly, because encryptors must change a lot o...
GhostEngine mining attacks kill EDR security using vulnerable drivers
News

GhostEngine mining attacks kill EDR security using vulnerable drivers

It has been determined that a malicious crypto mining campaign known as "REF4578" is using a malicious payload called GhostEngine, which leverages insecure drivers to disable security products and launch an XMRig miner. In separate publications and shared detection rules to assist defenders in identifying and stopping these crypto-mining assaults, researchers from Elastic Security Labs and Antiy have highlighted the exceptionally sophisticated nature of these attacks. The origin and extent of the campaign are still unknown, though, as neither the report nor its specifics link the activity to recognized threat actors or provide information about targets or victims. The threat actor's attack begins with the execution of a program called "Tiworker.exe," which poses as a genuine Wind...