How Cybercriminals Are Using Legitimate Drivers to Defeat Antivirus and Deploy Ransomware

Listen to this Post

Featured Image

Introduction: The New Era of Cyberattacks Using Trusted Drivers

A recent cyberattack on a Brazilian enterprise has revealed a dangerous shift in the tactics cybercriminals use to bypass security defenses. Attackers are no longer relying solely on traditional malware but are increasingly exploiting legitimate, digitally signed drivers to disable antivirus (AV) software and unleash destructive ransomware. This strategy highlights a growing sophistication in cyber threats, where trusted system components become weapons in the hands of adversaries. Understanding these tactics is critical for organizations looking to defend themselves in an evolving threat landscape.

Unveiling the Attack: A Breakdown of the Cyber Intrusion

The attackers launched a Bring Your Own Vulnerable Driver (BYOVD) attack, abusing a legitimate driver called ThrottleStop.sys, originally designed to tweak CPU performance. Exploiting this driver’s critical vulnerability (CVE-2025-7771), they bypassed system security to install MedusaLocker ransomware. The intrusion began by compromising an SMTP server using valid Remote Desktop Protocol (RDP) credentials. From there, attackers leveraged the powerful credential-harvesting tool Mimikatz to extract further user credentials and used pass-the-hash techniques to move laterally within the network.

The core objective was to neutralize any security tools that could detect or stop their ransomware deployment. To achieve this, they uploaded and ran malicious files including an antivirus killer program (“All.exe”) and a renamed vulnerable driver (“ThrottleBlood.sys”), which terminated critical antivirus processes such as Microsoft Defender, Kaspersky, Symantec, and CrowdStrike.

The attack’s technical heart lies in kernel-mode exploitation: the vulnerable driver allowed attackers to execute commands with kernel privileges, a level of access usually reserved for trusted system operations. By hijacking kernel functions, the malware relentlessly killed any security process—even those automatically restarted by Windows—rendering traditional AV defenses ineffective.

What Undercode Say: In-Depth Analysis of the BYOVD Threat

This incident demonstrates a worrying evolution in ransomware attacks, where threat actors weaponize trusted components rather than relying solely on new malware strains. Using a digitally signed driver like ThrottleStop.sys turns Windows’ security model against itself. Normally, the kernel mode—where this driver operates—is highly protected, but vulnerabilities within signed drivers provide a backdoor for attackers.

The

Moreover, the use of undocumented Windows functions like NtQuerySystemInformation highlights how attackers probe deep into system memory to identify and manipulate kernel components. This level of sophistication goes beyond typical ransomware campaigns and signals a new arms race where defenders must rethink their strategies.

The BYOVD technique also points to the critical need for defense in depth. Relying on a single security solution leaves gaps when attackers exploit legitimate drivers. Multi-factor authentication, strict control of RDP access, network segmentation, and aggressive privilege management are no longer optional but essential. Additionally, organizations should actively monitor driver installations and suspicious kernel-mode activity as part of their security posture.

The attack underscores the broader issue that trusted software can become the weakest link. Vendors need to harden drivers against such vulnerabilities, and security platforms must develop better detection mechanisms specifically designed to counter BYOVD and kernel-level exploits.

Organizations that fail to adapt risk falling victim to increasingly stealthy ransomware campaigns, where attackers blend legitimate tools with malicious intent, staying under the radar until it’s too late.

🔍 Fact Checker Results

The use of ThrottleStop.sys with CVE-2025-7771 is a confirmed vector for kernel-level exploitation. ✅
MedusaLocker ransomware has been linked to BYOVD attacks in recent threat reports. ✅
Antivirus self-healing features can be bypassed by kernel-mode process termination. ✅

📊 Prediction: The Rise of BYOVD Attacks and Future Security Measures

As attackers continue to evolve, BYOVD attacks leveraging legitimate drivers will become more common and sophisticated. We can expect to see a surge in ransomware campaigns that incorporate kernel-mode exploits to disable security software and avoid detection. In response, security vendors will likely innovate new defensive layers that monitor driver integrity and kernel operations in real-time.

Future cybersecurity frameworks will have to integrate behavioral analytics to spot abnormal driver activities and enforce stricter validation for driver installations. Enterprises will also adopt more proactive incident response plans focusing on early detection of lateral movement and credential abuse.

The cat-and-mouse game between cybercriminals and defenders is reaching new depths within operating systems themselves, making it crucial for organizations to invest in comprehensive, multi-layered security strategies that protect beyond the traditional perimeter. Only through such an approach can they mitigate the escalating risks posed by these advanced, trusted driver exploits.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon