Ransomware gang caught using Microsoft-approved drivers to hack targets
Using this technique, the ransomware gang can drop malware that is inherently trusted by any Windows system, security researchers say.
Stay updated with breaking news from Windows Hardware Developer Program. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Using this technique, the ransomware gang can drop malware that is inherently trusted by any Windows system, security researchers say.
Microsoft has released its final monthly batch of security updates for 2022, fixing more than four dozen security holes in its various Windows operating systems and related software. The most pressing patches include a zero-day vulnerability in a Windows feature…
Microsoft disclosed that it suspended several developer program accounts that were able to obtain drivers certified by its Windows Hardware Developer Program that likely deployed ransomware.
Several cybersecurity firms have warned Microsoft that cybercriminals have been using signed malicious drivers to kill antivirus and EDR processes.
Malicious Windows drivers signed as legit by Microsoft have been spotted as part of a toolkit used to kill off security processes in post-exploitation cyber activity.