Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware

A large-scale campaign is turning a trusted Windows security driver into a weapon that shuts down protection tools before ransomware and remote access malware are dropped. The attacks abuse truesight.sys, a kernel driver from Adlice Software’s RogueKiller antivirus, and use more than 2,500 validly signed variants to quietly disable endpoint detection and response (EDR) and […]

The post Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: