Windows devices are being targeted by a novel hacking campaign leveraging two exploits in Chinese remote control software Sunlogin to facilitate Sliver post-exploitation toolkit deployment and Bring Your Own Vulnerable Driver attacks, BleepingComputer reports.
A financially motivated threat actor tracked as Scattered Spider was observed attempting to deploy Intel Ethernet diagnostics drivers in a BYOVD (Bring Your Own Vulnerable Driver) attack to evade detection from EDR (Endpoint Detection and Response) security products.
A threat actor that specializes in getting around multifactor authentication protection has added a new tool to its arsenal for infecting computers: Leveraging a known Windows weakness to compromise the operating system's kernel. The group is dubbed Scattered Spider by researchers at Crowdstrike. Others call it Roasted 0ktapus or UNC3944. Whatever the name, Crowdstrike says