logo

Hackers Weaponize 2,500+ Security Tools to Disable Endpoint Defenses Before Ransomware Attacks

ID: 201e6c04-49e3-543b-9329-7d03b67a2e9f

STIX ID: report--201e6c04-49e3-543b-9329-7d03b67a2e9f

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** The report describes a sophisticated campaign abusing a signed Windows kernel driver (truesight.sys v2.0.2) with an IOCTL-based arbitrary process termination vulnerability to kill security products, evade detection by generating thousands of signature-preserving variants, and deploy HiddenGh0st RAT and ransomware; the activity is attributed to the financially motivated Silver Fox actor and has spread to ransomware groups, affecting primarily organizations in mainland China and the wider APAC region, with low detection rates and concrete mitigation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.