Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
ID: 89accf80-3083-5ed5-bec3-7fb26cd1ffc5
STIX ID: report--89accf80-3083-5ed5-bec3-7fb26cd1ffc5
Feed Name: TrendAI Security Blog
This report details an active ransomware campaign that leverages a vulnerable, legitimately code-signed anti-cheat driver (mhyprot2.sys) to bypass privileges, terminate security processes, and enable mass deployment across a domain; it provides a full timeline of compromise (secretsdump, wmiexec, RDP, use of Domain Controller/Netlogon and PsExec/GPO), deep technical analysis of the driver control path used to kill AV via ZwTerminateProcess, PoCs demonstrating the driver's dangerous capabilities, IOCs (driver hash and Event ID 7045), and practical monitoring and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
