FILEMembers
FILE

2008-Signed Kernel Driver Still Evades Most Antivirus Engines

WinRing0.sys, a hardware-monitoring driver signed nearly two decades ago with a now-expired certificate chain, remains a live BYOVD tool flagged by YARA as LOLDrivers-cataloged. Despite 1,339 submissions since 2009, only 2 of 75 engines detect it.

Jul 24, 2026, 13:47 (UTC+9)Last seenJul 24, 2026Severity62ByCTX TeamActorTurlaIron HunterIOC6MITRE7

A driver signed nearly two decades ago — its entire certificate chain now flagged as time-invalid — has resurfaced in a small but sharply detailed record that puts vulnerable-driver tradecraft, not infrastructure, at the center of the story. The file is WinRing0.sys, a hardware-monitoring kernel driver, and it carries a signature chain minted in 2007~2008 that has since decayed into forensic wreckage: every intermediate certificate in the Authenticode chain, from signer Noriyuki MIYAZAKI…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence