Legacy Driver Exploitation Through Bypassing Certificate Verification
ID: fc63cc2f-d471-5e91-9d4d-d3fdb1b46029
STIX ID: report--fc63cc2f-d471-5e91-9d4d-d3fdb1b46029
Feed Name: ASEC
This report describes a 2024–2025 campaign that abused a vulnerable TrueSight.sys driver (legacy driver exploitation and certificate-padding manipulation related to CVE-2013-3900) to bypass Windows signature checks and Microsoft's driver blocklist, terminate security products, and deploy Gh0stRAT via phishing and messaging app distribution; Microsoft later updated its Vulnerable Driver Blocklist and vendors detected the modified driver and payloads (IOCs include MD5 hashes and OSS download URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
