They Got In Through SonicWall. Then They Tried to Kill Every Security Tool
ID: 8845f412-6c28-5adc-a3e6-3e7c0755f6b0
STIX ID: report--8845f412-6c28-5adc-a3e6-3e7c0755f6b0
Feed Name: Huntress Blog
In February 2026, Huntress investigated an intrusion where attackers with compromised SonicWall SSLVPN credentials deployed a wordlist-encoded EDR-killer that decoded and installed a revoked-but-signed EnCase kernel driver (OemHwUpd.sys) to gain kernel-level ability to terminate endpoint security; the intrusion was disrupted prior to ransomware deployment. The report details telemetry-based detection, the encoding/decoding and persistence mechanisms, abuse of driver IOCTLs to kill processes, systemic gaps in Driver Signature Enforcement, and provides IoCs (IPs, file paths, service name, and SHA-256 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
