
17-Year-Old Kernel Driver Powers 2026 Credential-Theft Campaign Across 7 Countries
Two new file samples — including an MSIL injector compiled May 8, 2026 — expand a trojanized-crack campaign from Brazil to seven countries across four continents. The five-stage attack chain pairs a LOLDrivers-listed kernel driver from 2008 with freshly built .NET payloads, combining credential theft and cryptomining under a single operator infrastructure fingerprint.
Since CTX Team's earlier coverage of a trojanized CorelDraw crack campaign targeting Brazil, two new file samples have surfaced that confirm the operator is not winding down — they are building out. The most recent addition carries a PE compilation timestamp of 2026-05-08 and was first submitted to VirusTotal just three days later, on May 11.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read