logo

Driver of destruction: How a legitimate driver is being used to take down AV processes

ID: 2fef6cc2-16a9-5023-a7a9-e2403fb59c33

STIX ID: report--2fef6cc2-16a9-5023-a7a9-e2403fb59c33

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2025-08-06

Date Updated: 2026-04-29

Author: Cristian Souza, Ashley Muñoz, Eduardo Ovalle, Francesco Figurelli, Anderson Leite

...
...

This report analyzes an incident in Brazil where attackers used valid RDP credentials and credential theft (Mimikatz) to move laterally and deploy a MedusaLocker ransomware, leveraging a malicious AV-killer (All.exe) that abuses a vulnerable signed driver (ThrottleStop.sys / CVE-2025-7771) to read/write physical memory, hijack kernel functions, and terminate many AV/EDR processes; the document includes technical analysis, IOCs, a YARA rule, TTP mapping, affected regions, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.