Driver of destruction: How a legitimate driver is being used to take down AV processes
ID: 2fef6cc2-16a9-5023-a7a9-e2403fb59c33
STIX ID: report--2fef6cc2-16a9-5023-a7a9-e2403fb59c33
Feed Name: Securelist by Kaspersky
Date Published: 2025-08-06
Date Updated: 2026-04-29
Author: Cristian Souza, Ashley Muñoz, Eduardo Ovalle, Francesco Figurelli, Anderson Leite
This report analyzes an incident in Brazil where attackers used valid RDP credentials and credential theft (Mimikatz) to move laterally and deploy a MedusaLocker ransomware, leveraging a malicious AV-killer (All.exe) that abuses a vulnerable signed driver (ThrottleStop.sys / CVE-2025-7771) to read/write physical memory, hijack kernel functions, and terminate many AV/EDR processes; the document includes technical analysis, IOCs, a YARA rule, TTP mapping, affected regions, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
