Signed Drivers, Silent Threats: Kernel-Level Attacks on Windows Escalate via Trusted Tools
ID: 3488de01-a234-5ded-adce-8aa4981946b6
STIX ID: report--3488de01-a234-5ded-adce-8aa4981946b6
Feed Name: Cyber Press
This report highlights an increasing trend of threat actors abusing legitimately signed Windows kernel drivers to deploy kernel-level malware and loaders: Group-IB identified over 620 malicious kernel drivers, more than 80 code-signing certificates, and around 60 WHCP accounts since 2020. It details the modular nature of attacks (first-stage signed drivers loading unsigned or signed second-stage payloads), the underground economy for EV certificates and WHCP accounts that enables driver signing abuse, and calls for stronger EV validation, deeper CA-Microsoft collaboration, and improved operational audits to protect the kernel trust model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
