Hackers Weaponize 2,500+ Security Tools to Disable Endpoint Defenses Before Ransomware Attacks
ID: 201e6c04-49e3-543b-9329-7d03b67a2e9f
STIX ID: report--201e6c04-49e3-543b-9329-7d03b67a2e9f
Feed Name: GBHackers
**Executive Summary:** The report describes a sophisticated campaign abusing a signed Windows kernel driver (truesight.sys v2.0.2) with an IOCTL-based arbitrary process termination vulnerability to kill security products, evade detection by generating thousands of signature-preserving variants, and deploy HiddenGh0st RAT and ransomware; the activity is attributed to the financially motivated Silver Fox actor and has spread to ransomware groups, affecting primarily organizations in mainland China and the wider APAC region, with low detection rates and concrete mitigation guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
