
APT28 Deploys 11-Year-Old Signed Kernel Driver in Layered Credential-Theft Campaign
A fake HSBC payment notification delivers a three-stage attack chain combining a decade-old signed vulnerable kernel driver, a SspiCli.dll sideloading payload, and an AgentTesla infostealer. The kernel driver, first seen in 2015 and still carrying a legitimate code signature, achieves only 3/76 detection while clearing the path for credential harvesting across ten industries and twenty-three countries.
A financially themed ZIP archive named HSBC_PAYMENT_ADVICE0293845678.zip is circulating as the opening move in a layered attack chain that deploys a signed vulnerable kernel driver first seen in 2015 alongside a freshly compiled DLL sideloading payload and an AgentTesla infostealer equipped with active sandbox-evasion logic.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read