3 ms·
This is a great writeup. It looks like this driver is being actively used in malware, too: https://www.fortinet.com/blog/threat-research/interlock-ransomware-n
by bri3d 8mo ago
This is a great writeup.
It looks like this driver is being actively used in malware, too: https://www.fortinet.com/blog/threat-research/interlock-ransomware-new-techniques-same-old-tricks https://www.fortinet.com/blog/threat-research/interlock-rans...
- svespalec 8mo agoThanks! I had no idea it was already being used in the wild. It's a good case study for why shipping signed drivers with exposed IOCTLs and weak authentication is such a liability, even if (especially if) the developer never bothers to even load them.