
WHQL-Signed Vulnerable Driver Hides in Unsigned Stealer Bundle
A twelve-file crimeware batch pairs Amadey, StealC, Lumma, and other commodity stealers with a single signed kernel driver that trips Elastic's vulnerable-driver detection rule. The driver is the only signed binary among eleven otherwise unsigned files, turning a routine stealer distribution run into one with a built-in defense-evasion escalation option.
A twelve-file submission batch built around commodity stealers and loaders carries one outlier that changes its risk profile entirely: a 34-kilobyte driver called ProcessMonitorDriver, signed through a legitimate Microsoft Windows Hardware Compatibility Publisher chain, that trips Elastic Security's `Windows_VulnDriver_ProcessMonitorDriver detection rule — the community's marker for a WHQL-blessed driver that is also abusable to kill security tooling.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read