logo

Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware

ID: fc654db2-cec4-5f1d-81f4-bb08722fc694

STIX ID: report--fc654db2-cec4-5f1d-81f4-bb08722fc694

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A widespread campaign is abusing the legitimately signed TrueSight kernel driver (truesight.sys) to disable endpoint protection on Windows hosts, using over 2,500 validly signed variants to evade defenses and enable ransomware and remote-access trojan deployments; initial access is via phishing or fake downloads, with staged payload delivery, persistence, and an obfuscated EDR-killer module that installs and invokes the vulnerable driver to terminate security processes, leaving victims blind to encryption or data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.