logo

Anatomy of a WHQL-Signed Windows Filtering Platform (WFP) Kernel-Resident Network Backdoor

ID: c49eb135-95f3-5669-b583-9ebab228c666

STIX ID: report--c49eb135-95f3-5669-b583-9ebab228c666

Feed Name: Nextron Systems

Threat Score
85/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Pierre-Henri Pezier

...
...

This report documents a malicious, WHQL-signed 64-bit Windows kernel driver (`wskmon.sys`) that implements a full-featured remote backdoor via a WFP stream callout, accepting encrypted, HMAC-SHA256-authenticated commands over the network and executing them entirely in kernel mode; it includes build and signing metadata, SHA-256, and detection/reverse-engineering findings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.