Tag
Fake LastPass Authenticator Installer Deploys BYOVD Security-Disabling Kernel Driver
1 rule 3 TTPsThreat actors are distributing a credential-stealing payload via fake GitHub repositories that uses a legitimate Microsoft-signed driver to disable security software via kernel-level process termination.
UAT-10147 Deploys SPECTRE Cross-Platform Backdoor
2 rules 6 TTPs 2 IOCsThe threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.
Threat Actors Disabling AV and EDR Solutions
2 rules 2 TTPsThreat actors are actively disabling antivirus and EDR solutions through abusing Windows Firewall rules, uninstalling agents, and exploiting vulnerable drivers (BYOVD) to establish persistence, move laterally, and deploy ransomware undetected.
TVicPort64.sys Arbitrary Physical Memory Mapping LPE
2 rules 1 TTPThe TVicPort64.sys driver, signed by EnTech Taiwan in 2006, is vulnerable to arbitrary physical memory mapping, enabling local privilege escalation on Windows systems.