logo

ThreadSleeper: Suspending Threads via GMER64 Driver

ID: f2dc949a-9e84-5166-8fae-5320d7be2cf2

STIX ID: report--f2dc949a-9e84-5166-8fae-5320d7be2cf2

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This blog post reverse-engineers the gmer.sys/gmer64 Windows kernel driver (linked to Blackout activity) and demonstrates that due to an insecure device security descriptor and exposed IOCTLs an unprivileged (medium integrity) user can suspend arbitrary threads in protected processes via ZwSuspendThread, enabling stealthy disruption of EDR/PPL processes; it includes step-by-step analysis, a proof-of-concept, impact discussion, and defensive recommendations (ETW telemetry and driver blocking).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.