
WHQL-Signed Kernel Driver With 2/76 Detections Opens Stealc v2 Kill Chain
A 34 KB Windows kernel driver bearing a Microsoft WHQL certificate chain achieves only 2 of 76 detections on VirusTotal, serving as the opening move in a five-stage campaign that delivers Stealc v2 credential stealers and clipboard hijackers targeting cryptocurrency wallets. The driver, masquerading as a Safetica process-monitor component, neutralises endpoint defences before a single payload executes, enabling a layered financial-theft stack that bypasses Chromium app-bound encryption.
A 34-kilobyte Windows kernel driver signed by the Microsoft Windows Hardware Compatibility Publisher — carrying a WHQL certificate chain that traces back to Microsoft's own root authority — is being deployed as the opening move in a five-stage financial-theft campaign that ultimately delivers Stealc v2 credential stealers capable of bypassing Chromium app-bound encryption and in-process clipboard hijackers targeting cryptocurrency wallet addresses.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read