
2008-Signed Kernel Driver Still Evades Most Antivirus Engines
WinRing0.sys, a hardware-monitoring driver signed nearly two decades ago with a now-expired certificate chain, remains a live BYOVD tool flagged by YARA as LOLDrivers-cataloged. Despite 1,339 submissions since 2009, only 2 of 75 engines detect it.
A driver signed nearly two decades ago — its entire certificate chain now flagged as time-invalid — has resurfaced in a small but sharply detailed record that puts vulnerable-driver tradecraft, not infrastructure, at the center of the story. The file is WinRing0.sys, a hardware-monitoring kernel driver, and it carries a signature chain minted in 2007~2008 that has since decayed into forensic wreckage: every intermediate certificate in the Authenticode chain, from signer Noriyuki MIYAZAKI…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read