Threat actors use a new hacking tool dubbed AuKill to disable Endpoint Detection & Response (EDR) Software on targets' systems before deploying backdoors and ransomware in Bring Your Own Vulnerable Driver (BYOVD) attacks.
In such attacks, malicious actors drop legitimate drivers signed with a valid certificate and capable of running with kernel privileges on the victims' devices to disable security solutions and take over the system.
Ransomware gangs abuse Process Explorer driver to kill security software
Malwarebytes Threat Alert | RiskWare.ProcessHacker
In such attacks, malicious actors drop legitimate drivers signed with a valid certificate and capable of running with kernel privileges on the victims' devices to disable security solutions and take over the system.
Ransomware gangs abuse Process Explorer driver to kill security software
Malwarebytes Threat Alert | RiskWare.ProcessHacker