SteelFox Leverages Signed Windows Drivers to Attack Kernel


This week, the SonicWall Capture Labs threat research team investigated a sample of SteelFox malware.

This is bundled with “software activators” for JetBrains and Foxit PDF readers. During installation, they run as a service and use vulnerable signed Windows drivers to exploit and attack the kernel. Secondarily, cryptominers such as XMRig are run in memory via AppInfo, as well as network communications. The sample is detected as an executable without a packer or protector; however, the file entropy shows that it is, in fact, packed.

Read more…
Source: SonicWall


Sign up for our Newsletter


Related:

  • Malicious Apple Shortcuts could bypass security features to steal data

    February 23, 2024

    Apple Shortcuts could be used to steal sensitive data from Apple devices due to a high-severity vulnerability. Shortcuts is an app created by Apple that allows users to create customized task workflows on Apple devices and automate processes using a combination of built-in functions. Custom shortcuts can be exported and shared with other users, and shortcuts ...

  • The Building Resilience to Cognitive Warfare Technical Exchange Meeting

    February 23, 2024

    In September 2023, MITRE hosted a Technical Exchange Meeting (TEM) titled Building Resilience to Cognitive Warfare with participants from MITRE, the Department of Defense, and the Australian Defense Force, whic h focused on securing the cognitive domain, including identifying national-level partnerships and innovation opportunities. This paper explores the emerging importance of cognitive security in the face ...

  • Charlotte Cowles’s $50,000 Scam Article, Anyone Can Become a Victim

    February 23, 2024

    “You must follow my directions very carefully. We do not have much time.” These are some of the words scammers used to influence and ultimately defraud Charlotte Cowles, a financial columnist at New York Magazine, in an elaborate imposter scam that cost Cowles and her family $50,000. In this one line alone, there are two classic ...

  • Canada: RCMP confirms ‘alarming’ cyber event targeting its networks

    February 23, 2024

    The Royal Canadian Mounted Police confirmed to CTV News on Friday that it was dealing with a cyber event that targeted its networks, forcing it to launch a criminal investigation into the breach. “At this time, there is no impact on RCMP operations and no known threat to the safety and security of Canadians,” RCMP media ...

  • China’s top anti-espionage authority warns of secret leaks through smart wearable devices

    February 23, 2024

    China’s top anti-espionage authority warned on Friday that various smart wearable devices may become “cyber spies” used by foreign intelligence agencies to carry out espionage activities, posing a threat to national security. The Ministry of State Security (MSS) said on its official WeChat account on Friday that when smart wearable devices are connected to smartphones via ...

  • “To live is to fight, to fight is to live! – IBM ODM Remote Code Execution

    February 22, 2024

    In previous blogs, watchTowr researchers discussed some of the big players in the enterprise software space, but there is one that they have not mentioned before, that is – quite frankly – the heavy-weight champion of the world in terms of applications for large enterprises. With over a hundred years of experience, a founder and leader ...