#driver


Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Sep 26, 2026 // 21:27

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The […]

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

Sep 22, 2026 // 00:12

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer […]

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Aug 27, 2026 // 14:10

Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. […]

Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot

Aug 21, 2026 // 18:56

Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations […]

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Aug 11, 2026 // 23:50

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in […]

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Jul 9, 2026 // 14:32

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense […]

Ransomware (Qilin, Warlock) exploits driver flaws to disable over 300 EDR security tools.

Apr 6, 2026 // 13:08

Cisco Talos and Trend Micro have found that threat actors using Qilin and Warlock ransomware are employing the bring your own vulnerable driver (BYOVD) method […]

Malicious ads resembling tax services spread ScreenConnect malware. The attack leverages a Huawei driver to bypass endpoint detection and response (EDR).

Mar 24, 2026 // 20:13

Since January 2026, a widespread ad-based malware operation has been observed targeting individuals in the U.S. searching for tax documents. This campaign uses fake installers […]