logo

Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus

ID: 89accf80-3083-5ed5-bec3-7fb26cd1ffc5

STIX ID: report--89accf80-3083-5ed5-bec3-7fb26cd1ffc5

Feed Name: TrendAI Security Blog

Threat Score
78/100

Date Published: 2026-01-01

Date Updated: 2026-08-21

...
...

This report details an active ransomware campaign that leverages a vulnerable, legitimately code-signed anti-cheat driver (mhyprot2.sys) to bypass privileges, terminate security processes, and enable mass deployment across a domain; it provides a full timeline of compromise (secretsdump, wmiexec, RDP, use of Domain Controller/Netlogon and PsExec/GPO), deep technical analysis of the driver control path used to kill AV via ZwTerminateProcess, PoCs demonstrating the driver's dangerous capabilities, IOCs (driver hash and Event ID 7045), and practical monitoring and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.