Researchers and threat intelligence sources detailed multiple signed Windows kernel drivers being abused to gain stealthy, high-privilege access and disable defenses. Nextron Systems analyzed wskmon.sys, a WHQL-signed Windows Filtering Platform driver that acts as a kernel-resident network backdoor by intercepting inbound TCP traffic and accepting encrypted, HMAC-authenticated commands marked with the magic bytes 7F 4E 54 46. The malware reportedly enables remote shell execution, arbitrary file writes, and shellcode execution directly from kernel context, allowing it to operate on Secure Boot systems while leaving few user-mode artifacts.
Separate LOLDrivers entries highlighted two additional signed drivers tied to ESET’s reporting on Gentlemen ransomware activity: Qihoo’s 360netmon_wfp.sys, tracked as Win64/VulnDriver.Qihoo360.A, and IObit Malware Fighter’s IMFForceDelete.sys, associated with CVE-2019-6494. The first can be abused to impair endpoint protections and support EDR-killing activity, while the second can be loaded to delete protected files regardless of access controls via IOCTL 0x8016E000. Across the reports, defenders were urged to block these drivers, monitor for suspicious signed driver loads and unexpected WFP callout registration, and hunt for indicators such as anomalous svchost.exe child processes, kernel-originated file overwrites, and protocol markers in network traffic.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Nextron Systems published technical analysis of wskmon.sys on 2026-06-26, describing it as a kernel-resident network backdoor that intercepts inbound TCP traffic and accepts encrypted, HMAC-authenticated commands. The report detailed capabilities including remote shell execution, arbitrary file writing, and shellcode execution from kernel context.
LOLDrivers published an entry for IMFForceDelete.sys, describing how ESET documented the GentleKiller Cleaner variant dropping the vulnerable driver without the .sys extension. The entry ties the abuse to defense impairment through protected-file deletion and includes detection guidance.
LOLDrivers published an entry for 360netmon_wfp.sys, a signed Qihoo/360.cn kernel driver documented by ESET as abused by the GentleKiller Network Blocker variant in Gentlemen ransomware intrusions. The entry recommends blocking the driver and provides detection and hunting resources.
The analyzed wskmon.sys sample was first submitted to VirusTotal from China on 2026-06-15. Nextron's analysis links this WHQL-signed driver to a kernel-resident network backdoor using Windows Filtering Platform stream callouts.
The wskmon.sys kernel driver bore an Authenticode certificate for Shenzhen Aolian Information Security Technology Co., Ltd. with a signing timestamp of 2026-04-17. This signing enabled the malicious driver to appear trusted within Microsoft's driver-signing ecosystem.
The IMFForceDelete.sys driver vulnerability was identified as CVE-2019-6494, allowing low-privileged users to delete files regardless of access controls via IOCTL 0x8016E000. This established the driver as abusable for defense impairment once loaded.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
nextron-systems.com
Open sourceloldrivers.io
Open sourceloldrivers.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.