logo

ToddyCat APT Targets ESET Bug to Load Silent Malware

ID: 34619b83-7480-5960-8d00-a0b4d5c45086

STIX ID: report--34619b83-7480-5960-8d00-a0b4d5c45086

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-04-07

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Kaspersky reported that the Chinese-speaking ToddyCat APT exploited a DLL search order hijacking vulnerability in ESET antivirus (CVE-2024-11859) to force the product to load a malicious version.dll delivering the TCESB payload, which can stealthily execute code and disable Windows kernel-level security; the actors also leveraged a vulnerable Dell driver (CVE-2021-36276) for kernel-level activity. ESET patched the issue in January and organizations are advised to monitor for installation of known-vulnerable drivers, unexpected kernel debug symbol loads, and to verify digital signatures of loaded system libraries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.