C&CMembers
C&C

WHQL-Signed Driver Blinds EDR a Year Before Crypto Theft Wave

A 34 KB kernel driver signed through Microsoft's WHQL chain was quietly staged on victim systems in May 2025, nearly a year before a coordinated wave of credential stealers and clipboard hijackers emerged. The pre-positioned driver terminates security tooling at the kernel level, clearing the way for a layered cryptocurrency theft chain that evades endpoint, DNS, and filesystem defenses simultaneously.

May 24, 2026, 14:38 (UTC+9)Last seenMay 24, 2026Severity100ByCTX TeamActorTA428ThunderCatsIOC38

A 34-kilobyte Windows kernel driver — signed with a legitimate Microsoft Hardware Compatibility Publisher certificate, bearing Safetica copyright strings, and detected by exactly two of 76 antivirus engines — was quietly staged on victim systems as early as May 2025. Nearly a year later, a coordinated wave of credential stealers, clipboard hijackers, and browser wallet harvesters began appearing in the wild, all beaconing to a two-IP cluster in a small, recently allocated autonomous system.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence