KDU (Kernel Driver Utility) is an open-source Windows utility used to bypass Driver Signature Enforcement and load unsigned kernel drivers into memory. In the provided reporting, it is not described as a standalone malware family but as an attacker tool embedded or invoked within larger intrusion toolchains. Huntress observed Chinese-speaking threat actors using kdu.exe as part of the MAESTRO VMware ESXi VM-escape toolkit during December 2025 intrusions. In that chain, MAESTRO/exploit.exe disabled VMware VMCI-related devices with devcon.exe, then used KDU to load the unsigned driver MyDriver.sys, which performed ESXi version detection, VMX memory leakage and corruption, sandbox escape, and deployment of the ESXi-resident VSOCKpuppet backdoor. The activity was associated with an intrusion that likely began via a compromised SonicWall VPN, involved use of a compromised Domain Admin account, RDP-based lateral movement, share enumeration, data staging for exfiltration, and attempted progression toward ransomware. The reporting ties the exploit chain with moderate confidence to VMware vulnerabilities CVE-2025-22226, CVE-2025-22224, and CVE-2025-22225. Separately, CrowdStrike reported a KDU module within the Lazarus-linked Gopuram backdoor ecosystem used to bypass driver signature enforcement and load an unsigned driver, which then collected information about installed AV filters and wrote it to C:\Windows\System32\catroot2\edb.chk.log. High-confidence indicators directly mentioned for KDU-related activity include the filename kdu.exe and its use to load unsigned drivers such as MyDriver.sys.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ASRock AsrDrv107.sys and AsrDrv107n.sys are ASRock IO driver builds listed as KDU providers for ASRock Motherboard Utility versions 3.0.498 and below. The driver family is associated with CVE-2020-15368 and exposes low-level privileged access primitives used by KDU.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"KDU Kernel Driver Utility ... allows an attacker to bypass driver signature enforcement. The utility is used to load an unsigned driver..."
9 distinct techniques documented for this family, organized by ATT&CK tactic.
KDU uses a vulnerable driver of legitimate software to access arbitrary kernel memory with read/write attributes
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used to load unsigned kernel drivers by bypassing Windows Driver Signature Enforcement, enabling execution of malicious drivers as part of the ESXi escape chain.
Tool used to load an unsigned kernel driver as part of the VM-escape exploitation workflow.
Utility used as a Gopuram module to bypass driver signature enforcement and load an unsigned driver; the loaded driver enumerates installed AV filters and writes results to a log file (C:\Windows\System32\catroot2\edb.chk.log).
Open-source BYOVD-style loader used here to bypass Windows Driver Signature Enforcement and map/load the unsigned exploit driver (MyDriver.sys) into kernel memory to enable the VM-escape chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.