FILEMembers
FILE

WHQL-Signed Vulnerable Driver Hides in Unsigned Stealer Bundle

A twelve-file crimeware batch pairs Amadey, StealC, Lumma, and other commodity stealers with a single signed kernel driver that trips Elastic's vulnerable-driver detection rule. The driver is the only signed binary among eleven otherwise unsigned files, turning a routine stealer distribution run into one with a built-in defense-evasion escalation option.

Aug 16, 2026, 14:57 (UTC+9)Last seenAug 16, 2026Severity77ByCTX TeamIOC17MITRE40RegionsALDEEC

A twelve-file submission batch built around commodity stealers and loaders carries one outlier that changes its risk profile entirely: a 34-kilobyte driver called ProcessMonitorDriver, signed through a legitimate Microsoft Windows Hardware Compatibility Publisher chain, that trips Elastic Security's `Windows_VulnDriver_ProcessMonitorDriver detection rule — the community's marker for a WHQL-blessed driver that is also abusable to kill security tooling.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence