Attackers used a Microsoft-attested Windows driver to disable 145 security tools
Daily Cyber News: Attackers used a Microsoft-attested Windows driver to disable 145 security tools
Victims could lose passwords, browser sessions, and cryptocurrency data after a malware campaign used a trusted-looking Windows driver to disable endpoint protection. Attackers created fake GitHub pages that impersonated LastPass Authenticator, although LastPass systems, services, and customer vaults were not compromised. The downloaded payload deployed a Microsoft-attested Windows kernel driver with 145 hardcoded process names associated with antivirus and endpoint security products.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, malware, windows, Microsoft-attested Windows, Attackers, used, Microsoft-attested, driver.