Ransomware Groups Exploit Legit IT Tools to Bypass Antivirus
ID: b0957a1e-4f27-5bc8-a9ff-3ca2da5e53a4
STIX ID: report--b0957a1e-4f27-5bc8-a9ff-3ca2da5e53a4
Feed Name: HackRead
Threat Score
Seqrite research describes a “dual-use dilemma” where legitimate system utilities (like Process Hacker and IOBit Unlocker) are being repurposed by ransomware operators to disable antivirus, gain SYSTEM/kernel-level control, steal credentials, and delete logs—techniques observed across multiple ransomware campaigns (LockBit 3.0, Dharma, Phobos, Makop, MedusaLocker) and increasingly packaged into RaaS kits that may adopt AI-assisted methods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
