Back to Hub

Akira Ransomware Now Hijacks Intel Drivers to Disable Microsoft Defender

Imagen generada por IA para: El ransomware Akira ahora secuestra controladores Intel para desactivar Microsoft Defender

The cybersecurity landscape faces a new threat as researchers uncover the Akira ransomware group's latest innovation - weaponizing legitimate Intel drivers to disable critical security protections. This sophisticated attack vector represents a dangerous evolution in ransomware tactics, marking one of the first widespread cases of attackers abusing trusted hardware vendor components to bypass security software.

Technical Analysis:
The attack chain begins with the compromise of enterprise networks through common initial access vectors like phishing or exposed RDP ports. Once established, attackers deploy a modified version of the Intel Ethernet diagnostics driver (e1d65x64.sys), which includes functionality to disable Microsoft Defender's real-time protection. By leveraging the driver's legitimate digital signature and elevated privileges, the malware can tamper with security settings without triggering standard detection mechanisms.

Impact and Implications:
This technique poses particular danger because:

  1. It bypasses traditional signature-based detection
  2. It exploits the inherent trust in digitally-signed vendor components
  3. It requires no zero-day vulnerabilities, using existing driver capabilities
  4. It leaves minimal forensic traces compared to other defense evasion methods

Defensive Recommendations:
Security teams should implement:

  • Application allowlisting for driver installations
  • Enhanced monitoring of driver loading events
  • Network segmentation to limit lateral movement
  • Regular review of installed drivers in enterprise environments

The emergence of this technique suggests ransomware groups are investing significantly in defense evasion research, likely inspiring copycat attacks across the cybercriminal ecosystem.

Original source: View Original Sources
NewsSearcher AI-powered news aggregation

Comentarios 0

¡Únete a la conversación!

Sé el primero en compartir tu opinión sobre este artículo.