Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: edr-evasion (5 articles)Clear

Lunex stealer abuses vulnerable AMD driver to disable security tools and steal credentials

Ontinue tied the Psychedelic Stealer, spread through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages, to a wider malware-as-a-service platform called Lunex. The chain starts with a bogus CAPTCHA that delivers a malicious MSI, which drops LunexLoader. The loader bypasses User Account Control through the CMSTPLUA COM object, then uses a bring-your-own-vulnerable-driver technique against the AMD Radeon Software driver PDFWKRNL.sys, affected by CVE-2023-20598, to escalate and evade defenses before fetching the stealer. Researchers note BYOVD is rarely used as a precursor to an infostealer. The final payload extracts credentials from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and installs a PowerShell-based browser Native Messaging Host for persistent remote filesystem access.

Check
Block the vulnerable PDFWKRNL.sys driver via Microsoft's blocklist, alert on ClickFix-style CAPTCHA lures, and hunt for rogue browser Native Messaging Hosts.
Affected
Windows users tricked by fake Cloudflare CAPTCHA lures run an MSI that loads a vulnerable AMD driver to disable defenses and steal browser and wallet data.
Fix
Enable the vulnerable driver blocklist, restrict MSI and script execution, block copy-paste run-dialog lures, and monitor for UAC bypass via CMSTPLUA.

Fake LastPass installer loads signed kernel driver that disables antivirus and endpoint defenses

LastPass and Delphos Labs reported a fake LastPass Authenticator installer, hosted on a lookalike GitHub page, that installs a Windows kernel driver to shut off security software before a password stealer runs. The driver, named Alinubx.sys, was signed through Microsoft's hardware-compatibility program, scored zero detections on VirusTotal in August, and was not on Microsoft's blocklist. It carries 145 antivirus and security process names and terminates each from the kernel, below where endpoint tools can see or block it. The installer uses DLL side-loading through a renamed Microsoft debugger, escalates to SYSTEM, and ships in padded 128 to 148 MB archives to evade size-limited scanners.

Check
Warn users to install LastPass Authenticator only from official stores, and hunt endpoints for Alinubx.sys, vsdbg side-loading, and unexpected kernel-mode drivers.
Affected
Windows hosts where a user runs the fake installer get a signed kernel driver that silently kills antivirus and endpoint detection before credential theft.
Fix
Deploy Microsoft's vulnerable driver blocklist, restrict driver loading, block the lookalike GitHub domain, and alert on mass termination of security processes.

Microsoft Defender's own boot driver can be turned against security tools

Check Point researchers showed at Black Hat that Microsoft Defender's own legitimately signed boot-time cleanup driver, BTR.sys, can be abused to delete security software during startup. The driver, bundled inside Defender to finish removing malware after a reboot, can perform arbitrary kernel-level file and registry operations, and a released proof-of-concept wiped the entire Defender stack from a fully updated Windows 11 machine with tamper protection on. Unlike bring-your-own-vulnerable-driver attacks, this uses a driver present in every Windows since Windows 7, so it cannot be blocklisted. It requires administrator rights with a specific privilege, so Microsoft considers it a trust-boundary issue rather than a bug and will not patch it.

Check
Restrict the SeLoadDriverPrivilege to only accounts that truly need it, since the technique depends on it, and build detection for unexpected loading of the BTR.sys boot driver.
Affected
Windows systems from Windows 7 through 11 where an attacker gains administrator rights with SeLoadDriverPrivilege; they can use Defender's own signed boot driver to delete endpoint security tools before those tools load.
Fix
Limit local administrator rights and the driver-load privilege, monitor for boot-time driver abuse and security services vanishing, and prioritize detection engineering while the technique is public but not yet seen in attacks.

Akira ransomware reboots Windows into Safe Mode to switch off security tools

Huntress detailed an Akira ransomware intrusion that reached in through an exposed SonicWall VPN and then forced Windows into Safe Mode to disable defenses. Because Safe Mode starts only a minimal set of services, the endpoint detection tools and Microsoft Defender did not load, leaving the attacker free to run their encryptor. The twist is that Safe Mode also starves the system of virtual memory, and thirteen seconds after the reboot the encryptor ran out of memory and crashed, so files were not encrypted, though the attacker still stole data. The technique remains a useful evasion play worth detecting even when the payload fails.

Check
Alert on boot-configuration changes and Safe Mode boots, watch for security services stopping and tools added to the Safe Mode service list, and require multi-factor authentication on every VPN account.
Affected
Windows environments reachable through exposed or weakly protected VPNs; an attacker who gains access can reboot endpoints into Safe Mode to bypass endpoint detection and Defender before attempting encryption or theft.
Fix
Require multi-factor authentication on VPNs and alert on failed login bursts, monitor for msconfig and bcdedit changes and Safe Mode boot events, and run security tooling in Safe Mode where supported.

AI-built ransomware toolkit uses Cursor and Claude Opus agents to automate EDR evasion and Active Directory discovery, Sophos finds

Sophos has detailed a threat actor using an AI-assisted ransomware toolkit that automates Active Directory discovery and EDR evasion. Tool and payload development was aided by Cursor and Claude Opus agents across coding, analysis, and revision, with some agents tasked to scrape security-research posts for fresh bypass techniques; resulting malware was tested in VMs against Sophos, CrowdStrike, and Microsoft EDR. The framework includes Cobalt Strike profiles mimicking legitimate web traffic, a Telegram-bot C2, Python shellcode injectors preserving host-binary functionality, and a Cloudflare Worker front-end redirector. Despite the AI orchestration, the workflow is entirely human-driven. Operator logs and a ransomware-leak-site reference confirmed criminal, not red-team, use.

Check
Hunt endpoints for payloads under C:\Users\*\Documents\test, Telegram-bot C2 traffic, and Cobalt Strike beacons fronted by Cloudflare Workers. Apply Sophos IoCs across EDR-monitored hosts.
Affected
Organizations relying on EDR signatures alone. This toolkit was AI-tuned specifically to bypass Sophos, CrowdStrike, and Microsoft EDR, and routes C2 through Telegram and Cloudflare Workers to blend in.
Fix
Layer behavioral detection and AD-tiering on top of EDR. Block unauthorized Telegram API and anomalous Cloudflare Worker egress. Monitor for AD-discovery patterns and shellcode injection into signed binaries.