Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign
ID: 951da2f7-40ac-50e0-8421-4bf70892ccf8
STIX ID: report--951da2f7-40ac-50e0-8421-4bf70892ccf8
Feed Name: Check Point Research
**Check Point Research uncovered a large-scale campaign (mid‑2024 to early 2025) in which attackers abused a legacy Truesight.sys driver (v2.0.2) — creating thousands of validly signed variants to bypass detection and the Microsoft Vulnerable Driver Blocklist — to deploy an EDR/AV killing module that terminates security products via IOCTL and ultimately deliver Gh0st RAT variants; infrastructure and victims were concentrated in China, and CPR coordinated with MSRC leading to a blocklist update.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
