Anatomy of a WHQL-Signed Windows Filtering Platform (WFP) Kernel-Resident Network Backdoor
ID: c49eb135-95f3-5669-b583-9ebab228c666
STIX ID: report--c49eb135-95f3-5669-b583-9ebab228c666
Feed Name: Nextron Systems
Threat Score
This report documents a malicious, WHQL-signed 64-bit Windows kernel driver (`wskmon.sys`) that implements a full-featured remote backdoor via a WFP stream callout, accepting encrypted, HMAC-SHA256-authenticated commands over the network and executing them entirely in kernel mode; it includes build and signing metadata, SHA-256, and detection/reverse-engineering findings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
