logo

Legacy Driver Exploitation Through Bypassing Certificate Verification

ID: fc63cc2f-d471-5e91-9d4d-d3fdb1b46029

STIX ID: report--fc63cc2f-d471-5e91-9d4d-d3fdb1b46029

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-03-16

Date Updated: 2026-04-26

Author: ATCP

...
...

This report describes a 2024–2025 campaign that abused a vulnerable TrueSight.sys driver (legacy driver exploitation and certificate-padding manipulation related to CVE-2013-3900) to bypass Windows signature checks and Microsoft's driver blocklist, terminate security products, and deploy Gh0stRAT via phishing and messaging app distribution; Microsoft later updated its Vulnerable Driver Blocklist and vendors detected the modified driver and payloads (IOCs include MD5 hashes and OSS download URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.