
17-Year-Old Kernel Driver Powers 2026 Espionage Campaign Across Five Nations
A threat cluster tracked since April 2026 pairs freshly compiled commodity stealers with WinRing0x64.sys, a LOLDrivers-listed kernel driver signed in 2008, to achieve kernel-level access on unpatched endpoints. Targets span Brazil, India, Lithuania, Mexico, and Romania, with staging infrastructure on Aeza Group and C2 on Beget LLC in Russia.
A cryptominer, a clipboard hijacker, a reflective-loading stealer, and a Bring-Your-Own-Vulnerable-Driver instrument built from a kernel module first compiled in 2008 — this is the toolkit CTX Team has been tracking across targets in Brazil, India, Lithuania, Mexico, and Romania since late April 2026. The campaign's most operationally distinctive feature is not any single payload but the deliberate pairing of freshly compiled 2026-era commodity stealers with WinRing0x64.sys (sha256:…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read