Forgotten motherboard driver turns out to be perfect for slipping Windows ransomware past antivirus checks

General News

Summary

A kernel-level Windows driver for old PC motherboards has been abused by criminals to silently disable antivirus protections, and hold files to ransom. Sophos this month reported that an arbitrary read-write flaw in a digitally signed driver for now-deprecated Gigabyte hardware was recently used by ransomware, dubbed Robbinhood, to quietly switch off security safeguards on Windows 7, 8 and 10 machines. At that point, the ransomware exploits the security flaw in the Gigabyte driver to alter memory to bypass protection mechanisms and inject malicious code into kernel space, completely compromising the box and allowing the file-scrambling component to run unhindered. "This second driver then goes to great lengths to kill processes and files belonging to endpoint security products, bypassing tamper protection, to enable the ransomware to attack without interference." Instead, Sophos recommends admins limit who has superuser access, layer security protections to minimize the spread of malware and its damaging effects, enforce best practices with passwords and multi-factor authentication, and educate users so that the trojan cant get a foothold on their machines in the first place.

Classifications

industries
No industries detected
applications
Networking and Cloud

AskAI Classifications

Labels
No AI classifications detected

Linked Companies

Sophos
$500M to $1B