Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining elevated privileges, the malware deployed a kernel driver... The driver carried a Microsoft Windows Hardware Compatibility Publisher signature chain.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft-signed Windows kernel driver deployed by the fake LastPass Authenticator installer. It disables antivirus and EDR processes from kernel mode, persists as a service, and can re-kill security tools after reboot. Dormant capabilities include file hiding, process injection, and web-traffic redirection.
Malicious or repurposed Microsoft-attested Windows kernel driver used by the Rapuncel campaign. Renamed and registered as the NvFsFilter service, it terminates 145 hardcoded antivirus and EDR processes at kernel level, including tools protected by Protected Process Light, enabling the subsequent stealer activity.
Microsoft-signed malicious kernel driver disguised as an NVIDIA component and registered as the NvFsFilter service. It terminates a hardcoded list of 145 antivirus and EDR processes, including Protected Process Light-protected processes, and has additional dormant capabilities for file and registry hiding, DLL injection, interception, traffic manipulation, and port redirection.
A signed but vulnerable Windows kernel driver that exposes an IOCTL enabling arbitrary process termination through ZwTerminateProcess. It is abused as a bring-your-own-vulnerable-driver (BYOVD) component to disable AV/EDR processes from kernel mode.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.