Get a Pentest and security assessment of your IT network.

News

RobbinHood Ransomware Abuses Vulnerable Driver to Delete Security Products

Security researchers observed the RobbinHood ransomware family abusing a vulnerable driver to delete security products before initiating its encryption routine. The threat abused CVE-2018-19320 in a signed Gigabyte driver to circumvent security products on an infected machine. This technique allowed the ransomware to load its unsigned driver and use it to kill security processes listed in a PLIST.TXT file. As of this post, the driver was still available, and Verisign had not revoked the certificate used for the driver.”]

Source: https://securityintelligence.com/news/robbinhood-ransomware-abuses-vulnerable-driver-to-delete-security-products/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Terrorism WEEKLY DIGESTTHREAT INTELLIGENCE FEED 23rd Jul 2nd

News

Attacker.NET : Server Management & Security, Website Malware Removal & Website Security