BlackCat ransomware operators deployed a new signed kernel-mode driver to gain high-privilege access on Windows systems and interfere with endpoint protections before later-stage payloads were launched. The activity reflects a broader shift by sophisticated attackers toward kernel-layer techniques that can evade or disable EPP and EDR tools, allowing malicious code to remain hidden and defenses to be impaired early in the intrusion chain.
Researchers said threat actors are increasingly using rootkits as a practical way to bypass security controls, whether by developing the tooling themselves, buying it on underground markets, or obtaining code-signing certificates to make deployment appear legitimate. The report warned that such drivers can support targeted ransomware operations by suppressing detection and persistence controls, and it urged organizations to protect certificates, enforce MFA, maintain asset inventories and logging, use allowlisting, keep reliable backups, and apply layered monitoring to detect kernel-level abuse.

TTPs, infrastructure, and targeting history in one profile.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.