FILEMembers
FILE

17-Year-Old Kernel Driver Powers 2026 Credential-Theft Campaign Across 7 Countries

Two new file samples — including an MSIL injector compiled May 8, 2026 — expand a trojanized-crack campaign from Brazil to seven countries across four continents. The five-stage attack chain pairs a LOLDrivers-listed kernel driver from 2008 with freshly built .NET payloads, combining credential theft and cryptomining under a single operator infrastructure fingerprint.

Jun 13, 2026, 06:59 (UTC+9)Last seenJun 13, 2026Severity100ByCTX TeamIOC16MITRE58RegionsAUBDBRESLU

Since CTX Team's earlier coverage of a trojanized CorelDraw crack campaign targeting Brazil, two new file samples have surfaced that confirm the operator is not winding down — they are building out. The most recent addition carries a PE compilation timestamp of 2026-05-08 and was first submitted to VirusTotal just three days later, on May 11.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence