Friday, 9 May 2025
Subscribe
TrackNews Logo
  • Home
  • News
  • Politics
  • Niger Delta
  • Entertainment
  • Business
  • Health
  • Sports
  • Crime
  • Editorial
  • 🔥
  • News
  • Politics
  • Business
  • Breaking News
  • National
  • Entertainment
  • Crime
  • Sports
  • Niger Delta
  • Gist
Font ResizerAa
Track NewsTrack News
Search
Follow US
©2025 Track News Media. All Rights Reserved. | Website Designed By AfeesHost
Home » Blog » NCC warns of blackbyte ransomware that abuses legit driver to disable security products
News

NCC warns of blackbyte ransomware that abuses legit driver to disable security products

Track News
Last updated: October 9, 2022 9:57 am
Track News
Share
SHARE

By Adeleye Kunle

The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has flagged a high-impact threat to Windows operating system, the Blackbyte Ransomware, which has the capacity to bypass protections by disabling more than 1,000 drivers used by various security solutions.

The NCC-CSIRT said the BlackByte ransomware gang, which is using a new technique that researchers called, “Bring Your Own Vulnerable Driver,” is exploiting the security issue that allowed it to disable drivers that prevent multiple Endpoint Detection and Response (EDR) and antivirus products like Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security, from operating normally.

Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.

The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with high privileges on the system.

Two notable recent examples of BYOVD attacks include Lazarus, abusing a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the Genshin Impact game.

The NCC-CSIRT advisory recommended that system administrators protect against BlackByte’s new security bypassing trick by adding the particular MSI driver to an active blocklist, monitoring all driver installation events, and scrutinising them frequently to find any rogue injections that do not have a hardware match

TAGGED:NCC warns of blackbyte ransomware that abuses legit driver to disable security products
Share This Article
Email Copy Link Print
Previous Article World Post Day 2022: UPU urges stakeholders to take concrete steps to tackle climate change
Next Article EPL: A big threat – Souness names Arsenal player to cause problems for Liverpool
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad image

You Might Also Like

Prison Assistant dismissed for smuggling drugs into prison

By
Track News

Okowa, Omo-Agege seek arrest, trial of killers of eight persons in Delta community

By
Track News

Osun 2022: Why I Left PDP Peace Meeting – Senator Adeleke Opens Up

By
Track News

BBNaija winner, Miracle, now certified Instrument Rated Pilot

By
Track News
Track News
Facebook Twitter Youtube Instagram

About US

Track News is a leading news site with a primary focus on Nigeria and world news in general. Stay informed with our real-time coverage across politics, tech, entertainment, and more. Your reliable source for 24/7 news.

Top Categories
Usefull Links

© Track News Media. All Rights Reserved. | Website Designed By AfeesHost

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?