Threats Tagged 'driver abuse'
View all threats tagged with 'driver abuse'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'driver abuse'
Click on any threat for detailed analysis and mitigation recommendations
RONINGLOADER is a sophisticated multi-stage malware loader used by the DragonBreath APT group to deploy an updated variant of the gh0st RAT. It begins infection via trojanized NSIS installers disguised as legitimate software and employs advanced evasion techniques including signed driver abuse, thread-pool injection, and Protected Process Light (PPL) exploitation to disable Microsoft Defender. The loader terminates antivirus processes, applies custom Windows Defender Application Control (WDAC) policies, and injects payloads into trusted system processes to avoid detection. This campaign targets Chinese EDR tools but demonstrates advanced tactics that could be adapted elsewhere. The malware’s complexity and stealth capabilities pose a medium severity threat, with potential impacts on confidentiality and integrity. European organizations using Windows environments with Microsoft Defender could be at risk, especially those in critical infrastructure and government sectors. Mitigation requires tailored detection of abnormal driver behavior, WDAC policy monitoring, and restricting installation of unsigned drivers. Countries with high adoption of Microsoft Defender and strategic geopolitical interest in China-related espionage are most likely affected. Join the discussion | AlienVault OTX General | 11/19/2025, 08:54:30 UTC Added: 11/19/2025, 09:17:04 UTC |
The Gentlemen ransomware group has emerged as a sophisticated threat actor targeting multiple industries across 17 countries, with a focus on the Asia-Pacific region. Their campaign demonstrates advanced capabilities, including the use of custom tools to bypass enterprise endpoint protections, exploitation of legitimate drivers, Group Policy manipulation, and encrypted data exfiltration. The group's tactics involve thorough reconnaissance, adaptive defense evasion techniques, and systematic compromise of enterprise environments. They have shown the ability to tailor their approach based on the specific security solutions encountered, highlighting a significant evolution in ransomware operations. The attackers leveraged various tools and techniques for lateral movement, persistence, and ransomware deployment, including the abuse of privileged domain accounts and Group Policy Objects. Join the discussion | AlienVault OTX General | 09/09/2025, 11:34:12 UTC Added: 09/09/2025, 22:05:26 UTC |
Check Point Research uncovered an ongoing campaign by the Silver Fox APT group exploiting a previously unknown vulnerable driver to evade endpoint protection. The attackers used a Microsoft-signed WatchDog Antimalware driver to terminate protected processes on fully updated Windows systems. A dual-driver strategy ensured compatibility across Windows versions. Following disclosure, the vendor released a patched driver, but attackers quickly adapted by modifying it to bypass blocklists while preserving its valid signature. The campaign delivered ValleyRAT as the final payload, demonstrating sophisticated evasion techniques and highlighting the growing trend of weaponizing signed-but-vulnerable drivers to bypass security measures. Join the discussion | AlienVault OTX General | 08/28/2025, 13:26:31 UTC Added: 08/28/2025, 13:33:12 UTC |
Showing 1 to 3 of 3 results