logo

Ransomware Groups Exploit Legit IT Tools to Bypass Antivirus

ID: b0957a1e-4f27-5bc8-a9ff-3ca2da5e53a4

STIX ID: report--b0957a1e-4f27-5bc8-a9ff-3ca2da5e53a4

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Seqrite research describes a “dual-use dilemma” where legitimate system utilities (like Process Hacker and IOBit Unlocker) are being repurposed by ransomware operators to disable antivirus, gain SYSTEM/kernel-level control, steal credentials, and delete logs—techniques observed across multiple ransomware campaigns (LockBit 3.0, Dharma, Phobos, Makop, MedusaLocker) and increasingly packaged into RaaS kits that may adopt AI-assisted methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.