Ransomware gangs abuse Process Explorer driver to kill security software

alimac

Well-known member
VIP
Threat actors use a new hacking tool dubbed AuKill to disable Endpoint Detection & Response (EDR) Software on targets' systems before deploying backdoors and ransomware in Bring Your Own Vulnerable Driver (BYOVD) attacks.

In such attacks, malicious actors drop legitimate drivers signed with a valid certificate and capable of running with kernel privileges on the victims' devices to disable security solutions and take over the system.

Ransomware gangs abuse Process Explorer driver to kill security software

Malwarebytes Threat Alert | RiskWare.ProcessHacker
 
Back
Top