Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: byovd (6 articles)Clear

Lunex stealer abuses vulnerable AMD driver to disable security tools and steal credentials

Ontinue tied the Psychedelic Stealer, spread through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages, to a wider malware-as-a-service platform called Lunex. The chain starts with a bogus CAPTCHA that delivers a malicious MSI, which drops LunexLoader. The loader bypasses User Account Control through the CMSTPLUA COM object, then uses a bring-your-own-vulnerable-driver technique against the AMD Radeon Software driver PDFWKRNL.sys, affected by CVE-2023-20598, to escalate and evade defenses before fetching the stealer. Researchers note BYOVD is rarely used as a precursor to an infostealer. The final payload extracts credentials from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and installs a PowerShell-based browser Native Messaging Host for persistent remote filesystem access.

Check
Block the vulnerable PDFWKRNL.sys driver via Microsoft's blocklist, alert on ClickFix-style CAPTCHA lures, and hunt for rogue browser Native Messaging Hosts.
Affected
Windows users tricked by fake Cloudflare CAPTCHA lures run an MSI that loads a vulnerable AMD driver to disable defenses and steal browser and wallet data.
Fix
Enable the vulnerable driver blocklist, restrict MSI and script execution, block copy-paste run-dialog lures, and monitor for UAC bypass via CMSTPLUA.

Fake LastPass installer loads signed kernel driver that disables antivirus and endpoint defenses

LastPass and Delphos Labs reported a fake LastPass Authenticator installer, hosted on a lookalike GitHub page, that installs a Windows kernel driver to shut off security software before a password stealer runs. The driver, named Alinubx.sys, was signed through Microsoft's hardware-compatibility program, scored zero detections on VirusTotal in August, and was not on Microsoft's blocklist. It carries 145 antivirus and security process names and terminates each from the kernel, below where endpoint tools can see or block it. The installer uses DLL side-loading through a renamed Microsoft debugger, escalates to SYSTEM, and ships in padded 128 to 148 MB archives to evade size-limited scanners.

Check
Warn users to install LastPass Authenticator only from official stores, and hunt endpoints for Alinubx.sys, vsdbg side-loading, and unexpected kernel-mode drivers.
Affected
Windows hosts where a user runs the fake installer get a signed kernel driver that silently kills antivirus and endpoint detection before credential theft.
Fix
Deploy Microsoft's vulnerable driver blocklist, restrict driver loading, block the lookalike GitHub domain, and alert on mass termination of security processes.

Crime group uses AI to mass-hack servers and deploy a Linux rootkit backdoor

Cisco Talos detailed a financially motivated, Chinese-speaking group it tracks as UAT-10147 that breaks into internet-facing Windows and Linux web servers at scale and installs malware for data theft and search-engine-optimization fraud. The group weaves AI tools through its operations, from exploiting known vulnerabilities to generating payloads, and Talos even found AI-generated code comments left in the source of its Linux kernel rootkit. Its cross-platform implant, SPECTRE, offers credential theft, process injection, encrypted command-and-control, and driver-based bypassing of endpoint detection. Investigators also recovered prompt logs from AI coding assistants on the attackers' own machines, a concrete look at adversaries using the same agent tools defenders do.

Check
Patch internet-facing web servers promptly since the group exploits known flaws at scale, enforce protections that block unsigned driver loads, and deploy endpoint detection with kernel-level visibility on Windows and Linux.
Affected
Organizations running internet-facing IIS or Linux web servers with unpatched known vulnerabilities; the group gains access at scale, deploys a rootkit and cross-platform backdoor, disables endpoint detection, and steals credentials and data.
Fix
Prioritize patching exposed servers, enable hypervisor-protected code integrity to counter driver-based evasion, monitor east-west traffic from web servers to internal Linux hosts, and hunt for kernel rootkits and unexpected HTTPS beacons.

Cruciferra crypter uses vulnerable drivers and process ghosting to hide malware

Researchers detailed Cruciferra, a crypter service that packages Windows malware to evade detection using two notable techniques. It brings a vulnerable signed driver to disable security tooling, an approach known as bring-your-own-vulnerable-driver, and it uses process ghosting, where a malicious file is deleted before its code is mapped into a running process, so the running program has no backing file for tools to inspect. Together these let common payloads run while sidestepping many endpoint defenses. Crypter services matter because they lower the skill needed to deploy malware stealthily, letting many separate actors wrap their payloads in the same evasion layer rather than building it themselves.

Check
Enable vulnerable driver blocklisting on Windows, hunt for known bad drivers being loaded, and ensure endpoint tooling can detect process ghosting rather than relying on scanning files on disk.
Affected
Windows environments relying on file-based or easily disabled endpoint defenses; Cruciferra-wrapped malware disables protections through a vulnerable driver and runs with no backing file to scan.
Fix
Turn on Microsoft's vulnerable driver blocklist, restrict driver loading, deploy behavior-based detection that catches process ghosting and driver abuse, and alert on unexpected kernel driver installs.

GodDamn ransomware uses a Microsoft-signed malicious driver to disable defenses

Symantec detailed GodDamn, a ransomware operation that disables endpoint defenses using PoisonX, a malicious kernel driver its developers managed to get signed by Microsoft, an unusual escalation over the more common tactic of abusing a legitimate vulnerable driver. In an early-June attack, the operators used AnyDesk for remote access and a credential-harvesting toolkit that pulls passwords from browsers, Windows Credential Manager, cached domain credentials, email clients, and network traffic, before deploying the ransomware. Alongside the signed driver, they ran a user-mode tool disguised as a Symantec product to blind security software. Symantec links GodDamn to a developer it tracks as Hyadina and says the group is actively improving its defense-evasion capabilities.

Check
Watch for bring-your-own-driver activity and processes masquerading as security products, audit remote-access tools like AnyDesk in your environment, and monitor for credential-harvesting across browsers and Windows credential stores.
Affected
Windows organizations where attackers gain a foothold; GodDamn uses a Microsoft-signed malicious driver to switch off endpoint defenses, harvests credentials broadly, then encrypts systems, making detection before deployment much harder.
Fix
Enable driver block lists and tamper protection, restrict who can load kernel drivers, tightly control remote-access software, enforce phishing-resistant MFA, and keep monitored offline backups so encryption stays recoverable.

DragonForce ransomware hid command traffic inside Microsoft Teams for months

Symantec reports that DragonForce ransomware operators stayed hidden inside a major US services firm's network for up to two months by disguising their command-and-control traffic as ordinary Microsoft Teams activity. A new Go-based backdoor, Backdoor.Turn, grabs an anonymous Teams visitor token, routes through a legitimate Microsoft Teams relay server, and then tunnels to the attackers' real server, so defenders watching the network only see connections to genuine Microsoft infrastructure. It is the first known malware to abuse Teams relay servers this way. The attackers also used a custom malicious driver to disable defenses, and installed the backdoor after deploying ransomware, suggesting they kept access for a return visit or to resell.

Check
Hunt for anomalous QUIC and Teams-relay traffic and unexpected processes making Teams connections, and review hosts for suspicious drivers, new accounts, and weakened password or firewall settings.
Affected
Organizations targeted by DragonForce; because the backdoor blends into legitimate Microsoft Teams traffic, network monitoring alone may miss it, leaving internet-facing database servers and weak segmentation as entry points.
Fix
Patch internet-facing SQL and other servers, enforce least privilege and driver-signing controls, monitor for Teams-relay abuse and BYOVD activity, and maintain tested offline backups and network segmentation to limit ransomware impact.