More

    New malware exploits trusted Windows drivers to get around security systems – here’s how to stay safe




    • Chinese threat group abused a vulnerable WatchDog Antimalware driver to disable antivirus and EDR tools
    • Attackers also leveraged a Zemana Anti-Malware driver (ZAM.exe) for broader compatibility across Windows
    • Researchers are urging IT teams to update blocklists, use YARA rules, and monitor for suspicious activity

    Chinese hackers Silver Fox have been seen abusing a previously trusted Windows driver to disable antivirus protections and deploy malware on target devices.

    The latest driver to be abused in the age-old “Bring Your Own Vulnerable Driver” attack is called WatchDog Antimalware, usually part of the security solution of the same name.

    https://cdn.mos.cms.futurecdn.net/BsnMKVyyNGEZMWVUsFD6vn.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img