Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware
ID: fc654db2-cec4-5f1d-81f4-bb08722fc694
STIX ID: report--fc654db2-cec4-5f1d-81f4-bb08722fc694
Feed Name: cybersecurityNews.com
A widespread campaign is abusing the legitimately signed TrueSight kernel driver (truesight.sys) to disable endpoint protection on Windows hosts, using over 2,500 validly signed variants to evade defenses and enable ransomware and remote-access trojan deployments; initial access is via phishing or fake downloads, with staged payload delivery, persistence, and an obfuscated EDR-killer module that installs and invokes the vulnerable driver to terminate security processes, leaving victims blind to encryption or data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
