A ransomware actor abused the legitimate mhyprot2.sys anti-cheat driver from the game Genshin Impact to terminate antivirus and endpoint protection processes before encrypting systems. Trend Micro reported that the attacker dropped and installed the signed driver, then used it to kill security tools by exploiting the driver's kernel-level privileges, allowing the intrusion to proceed with reduced detection and resistance.
The technique highlights a bring-your-own-vulnerable-driver style tradecraft in which trusted or signed drivers are repurposed to bypass defenses and gain powerful access on Windows endpoints. By weaponizing a legitimate game anti-cheat component rather than custom malware alone, the actor was able to undermine security products and improve the chances of successful ransomware deployment, underscoring the need for driver blocklists, application control, and monitoring for unexpected driver installation on enterprise systems.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Trend Micro published research describing a ransomware actor abusing the Genshin Impact anti-cheat driver to terminate antivirus processes. The report publicly documented the technique and its use in real-world attacks.
A researcher analyzed a ransomware campaign using the legitimate mhyprot2.sys gaming driver to terminate security processes and linked its ransom note TOX ID to Rever ransomware. The analysis also identified associated AVG.MSI, AVG.exe, HelpPane.exe, svchost.exe, and logon.bat artifacts and recovered the batch script and ransom note through sandbox execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.