Automatically translated.View original post

Use the Bypass vulnerability to shut down Microsoft Defender. 🚨

Windows Defender, which used to be like Windows' first shield, has now become a new target of the Akira ransomware gang. Over the years, it has evolved to be almost an antivirus that many people rely on comfortably, but hackers find a way to shut it down through "Bring Your Own Vulnerable Driver" (BYOVD) attacks or exploiting vulnerable drivers.

.

This is an Intel driver named rwdrv.sys that is normally used on ThrottleStop for customizing CPUs. The first step of the attack is not complicated at all. Just trick the victim into clicking a link, downloading a file, or installing a fake software. Once this driver is installed, it will give the hacker Kernel permissions, and then load the optional driver hlpdrv.sys to completely shut down the Microsoft Defender by modifying the value in the Registry through regedit.exe.

.

Once the main armor is closed, it opens the way for malware, ransomware, or system penetration tools to work undetected. Most recently, Akira ransomware has been reported to extend its attacks to SonicWall's VPN devices, which some sources suggest may be related to a known vulnerability, not zero-day, as many are concerned.

.

The important thing is that this method is not just a test, but has been used since the middle of July, and has been found so much more and more, that experts like GuidePoint Security have to rule out YARA and publish IoCs for administrators to detect.

.

How to Protect for Ordinary Users

- Use an anti-virus supplement. Don't rely on the Defender alone.

- Be careful of clicking links or opening untrustworthy attachments.

- Avoid running commands or scripts that do not understand the operation.

- Keep updating Windows and its programs to the latest version.

- Enable two-step identity verification (2FA) on all accounts possible.

.

Source: cyberguy

# IT # Includes IT matters # Cough to know

2025/9/3 Edited to

... Read moreการโจมตีอย่างใช้ช่องโหว่ Bring Your Own Vulnerable Driver (BYOVD) กลายเป็นเทคนิคที่แฮกเกอร์นำมาใช้ในการแทรกซึมระบบของผู้ใช้ Windows ได้อย่างซับซ้อนและยากที่จะตรวจจับ เพราะอาศัยไดรเวอร์ที่ถูกพัฒนาขึ้นเพื่อวัตถุประสงค์ที่ถูกต้อง แต่กลับกลายเป็นช่องทางเข้าสู่ระบบได้โดยไม่ถูกแอนตี้ไวรัสจับได้ กรณีของไดรเวอร์ rwdrv.sys ซึ่งถูกใช้งานปกติกับโปรแกรม ThrottleStop เพื่อปรับแต่งซีพียูนี้ ถือเป็นตัวอย่างที่ชัดเจนว่าแฮกเกอร์สามารถใช้ประโยชน์จากไดรเวอร์ที่เก่าหรือมีช่องโหว่ได้อย่างไร เมื่อไดรเวอร์นี้ถูกติดตั้งลงในระบบแล้ว จะเปิดสิทธิ์ระดับ Kernel ให้กับแฮกเกอร์ทันที ทำให้สามารถโหลดไดรเวอร์เสริมอย่าง hlpdrv.sys เพื่อจุดประสงค์ปิด Microsoft Defender โดยแก้ไข Registry ผ่าน regedit.exe ซึ่งเป็นความเสี่ยงระดับสูงอย่างยิ่งสำหรับการรักษาความปลอดภัยของระบบ การปิด Microsoft Defender ถือเป็นการปิดเกราะป้องกันหลักของ Windows ทำให้ระบบเปิดช่องโหว่ให้กับมัลแวร์หลายประเภท เช่น แรนซัมแวร์ Akira ที่มีการรายงานว่าเริ่มขยายการโจมตีไปยังอุปกรณ์ VPN ของ SonicWall ด้วย ซึ่งสะท้อนถึงปัญหาด้านความปลอดภัยที่ต้องคอยอัปเดตและตรวจสอบเครื่องมือใหม่ ๆ อย่างต่อเนื่อง สำหรับผู้ใช้ทั่วไป คำแนะนำที่สำคัญคืออย่าพึ่งพาแอนตี้ไวรัสของ Windows Defender เพียงอย่างเดียว ควรติดตั้งโปรแกรมแอนตี้ไวรัสเสริมที่เชื่อถือได้ และอย่างระมัดระวังในการคลิกลิงก์หรือเปิดไฟล์แนบจากแหล่งที่ไม่น่าเชื่อถือ นอกจากนี้ การหลีกเลี่ยงการรันคำสั่งหรือสคริปต์ที่ไม่เข้าใจเป็นสิ่งสำคัญ รวมถึงการอัปเดต Windows และซอฟต์แวร์ต่าง ๆ ให้เป็นเวอร์ชันล่าสุดอย่างสม่ำเสมอ เพื่อลดช่องโหว่ที่แฮกเกอร์อาจโจมตี สุดท้ายการเปิดใช้งานการยืนยันตัวตนสองขั้นตอน (2FA) ในทุกบัญชีที่รองรับจะช่วยเพิ่มความปลอดภัยและลดความเสี่ยงจากการถูกแฮกบัญชีอย่างมาก ซึ่งทั้งหมดนี้เป็นแนวทางที่ผู้ใช้ควรตระหนักและปฏิบัติเพื่อลดความเสี่ยงจากการโจมตีผ่านช่องโหว่ BYOVD และภัยคุกคามอื่นๆ ที่กำลังขยายตัวอย่างรวดเร็วในปัจจุบัน การติดตามข่าวสารด้านความปลอดภัยไซเบอร์อย่างใกล้ชิด และการใช้เครื่องมือสแกนตรวจจับต่าง ๆ ที่ถูกพัฒนาขึ้นจากการวิเคราะห์ความเคลื่อนไหวของแฮกเกอร์เช่นกฎ YARA และ IoCs ที่เผยแพร่โดยผู้เชี่ยวชาญ เช่น GuidePoint Security จะช่วยให้องค์กรและผู้ใช้ทั่วไปสามารถป้องกันและตอบสนองกับภัยคุกคามได้อย่างรวดเร็วและมีประสิทธิภาพมากขึ้น