logo

Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign

ID: 951da2f7-40ac-50e0-8421-4bf70892ccf8

STIX ID: report--951da2f7-40ac-50e0-8421-4bf70892ccf8

Feed Name: Check Point Research

Threat Score
78/100

Date Published: 2025-02-24

Date Updated: 2026-04-27

Author: [email protected]

...
...

**Check Point Research uncovered a large-scale campaign (mid‑2024 to early 2025) in which attackers abused a legacy Truesight.sys driver (v2.0.2) — creating thousands of validly signed variants to bypass detection and the Microsoft Vulnerable Driver Blocklist — to deploy an EDR/AV killing module that terminates security products via IOCTL and ultimately deliver Gh0st RAT variants; infrastructure and victims were concentrated in China, and CPR coordinated with MSRC leading to a blocklist update.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.