Hackers Use Legitimate Drivers to Kill Antivirus Processes and Lower The System’s Defenses

In a sophisticated campaign first observed in October 2024, attackers have begun leveraging a legitimate driver to disable antivirus software across compromised networks. By abusing the ThrottleStop.sys driver—originally designed by TechPowerUp to manage CPU throttling—the malware gains kernel‐level memory access to terminate security processes at will. Initial access is most often achieved through stolen RDP […]

The post Hackers Use Legitimate Drivers to Kill Antivirus Processes and Lower The System’s Defenses appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: