
WHQL-Signed Driver Blinds EDR a Year Before Crypto Theft Wave
A 34 KB kernel driver signed through Microsoft's WHQL chain was quietly staged on victim systems in May 2025, nearly a year before a coordinated wave of credential stealers and clipboard hijackers emerged. The pre-positioned driver terminates security tooling at the kernel level, clearing the way for a layered cryptocurrency theft chain that evades endpoint, DNS, and filesystem defenses simultaneously.
A 34-kilobyte Windows kernel driver — signed with a legitimate Microsoft Hardware Compatibility Publisher certificate, bearing Safetica copyright strings, and detected by exactly two of 76 antivirus engines — was quietly staged on victim systems as early as May 2025. Nearly a year later, a coordinated wave of credential stealers, clipboard hijackers, and browser wallet harvesters began appearing in the wild, all beaconing to a two-IP cluster in a small, recently allocated autonomous system.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read