logo

Kasseika ransomware uses antivirus driver to kill other antiviruses

ID: 170d4599-1056-590f-bd2f-f962ffd19ea9

STIX ID: report--170d4599-1056-590f-bd2f-f962ffd19ea9

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kasseika is a newly identified ransomware campaign that uses a signed vulnerable driver (Martini.sys) in BYOVD attacks to disable antivirus, spreads via credential theft and PsExec lateral movement, encrypts files with ChaCha20/RSA, and extorts victims with a 50 BTC ransom demand; Trend Micro published the technical analysis and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.