News
NCC warns of blackbyte ransomware that abuses legit driver to disable security products
By Adeleye Kunle
The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has flagged a high-impact threat to Windows operating system, the Blackbyte Ransomware, which has the capacity to bypass protections by disabling more than 1,000 drivers used by various security solutions.
The NCC-CSIRT said the BlackByte ransomware gang, which is using a new technique that researchers called, “Bring Your Own Vulnerable Driver,” is exploiting the security issue that allowed it to disable drivers that prevent multiple Endpoint Detection and Response (EDR) and antivirus products like Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security, from operating normally.
Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.
The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with high privileges on the system.
Two notable recent examples of BYOVD attacks include Lazarus, abusing a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the Genshin Impact game.
The NCC-CSIRT advisory recommended that system administrators protect against BlackByte’s new security bypassing trick by adding the particular MSI driver to an active blocklist, monitoring all driver installation events, and scrutinising them frequently to find any rogue injections that do not have a hardware match
-
Politics3 days ago
2027: Akpabio Plots Presidential Ambition with El-Rufai as Running Mate
-
News3 days ago
Customs Officer Dies In National Assembly After Requesting For Water
-
Politics3 days ago
Huge crowd as Shettima visits Ganduje in Kano
-
Crime3 days ago
SON’s Finance Director Faces Investigation Over Massive Corruption Allegations
-
Gist6 days ago
Bugiri woman who died in accident returns home after burial
-
Health6 days ago
NDLEA Bursts Snake-guarded Shrine Housing Illicit Drugs in Edo
-
Crime3 days ago
Police arrests councillor, village head over alleged theft of community transformer
-
News3 days ago
Rivers crisis: Police declare ex-militant leader wanted