logo

A Valid Microsoft Signature Does Not Mean a Driver Is Safe by Lucie Cardiet

ID: 27dc3e68-f6e3-5a27-8034-a178f9fe1d05

STIX ID: report--27dc3e68-f6e3-5a27-8034-a178f9fe1d05

Feed Name: Vectra AI Blog

Threat Score
78/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

...
...

**Executive Summary:** The report describes BYOVD campaigns where ransomware operators (tracked as Hackledorb/DragonForce and observed via the GentleKiller framework) loaded legitimate, signed kernel drivers — including one without a CVE at time of attack — to disable security tools, exploiting a timing gap between vulnerability discovery/CVE assignment and Microsoft’s vulnerable-driver blocklist; defenders can detect pre-kill activity by monitoring Event ID 7045 and mitigate structurally via Memory Integrity (HVCI).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.