#loldriver — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #loldriver, aggregated by home.social.
-
Check Point details BTR.sys driver abuse: a signed Defender component turned into a kernel EDR/AV bypass with no exploit needed.
#BTRsys #EDRBypass #Windows #Defender #KernelSecurity #LOLDriver #CheckPoint #InfoSec
http://securityonline.info/btr-sys-driver-edr-bypass/?utm_source=mastodon&utm_medium=jetpack_social
-
An unknown threat actor is abusing a remote management tool called #TiFLUX as an initial access vector, targeting a broad range of potential victims by email. The attacks using this Brasil-originated commercial utility began in February, but really ramped up in April and the beginning of this month.
The lures employ a variety of #spam tropes, including bogus event invitations and business invoices/bills.
TiFLUX seems uniquely vulnerable to this kind of abuse; The installer package also installs an old version of UltraVNC as well as a vulnerable #loldriver that can elevate privileges. Weirdest of all, the attackers are also using this RMM to deploy other heavily-abused RMMs, including #Splashtop and #ScreenConnect to the devices that get hit. Those RMMs are connecting to IP addresses associated with known bulletproof hosts.
This is my first post at the @huntress blog: https://www.huntress.com/blog/tiflux-rmm-install