abuses – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 07 Aug 2025 00:53:12 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 abuses – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Akira ransomware abuses CPU tuning tool to disable Microsoft Defender https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/ https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/#respond Thu, 07 Aug 2025 00:53:11 +0000 https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/

Hacker staring at a box

Akira ransomware is abusing a legitimate Intel CPU tuning driver to turn off Microsoft Defender in attacks from security tools and EDRs running on target machines.

The abused driver is ‘rwdrv.sys’ (used by ThrottleStop), which the threat actors register as a service to gain kernel-level access.

This driver is likely used to load a second driver, ‘hlpdrv.sys,’ a malicious tool that manipulates Windows Defender to turn off its protections.

This is a ‘Bring Your Own Vulnerable Driver’ (BYOVD) attack, where threat actors use legitimate signed drivers that have known vulnerabilities or weaknesses that can be abused to achieve privilege escalation. This driver is then used to load a malicious tool that disables Microsoft Defender.

“The second driver, hlpdrv.sys, is similarly registered as a service. When executed, it modifies the DisableAntiSpyware settings of Windows Defender within \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware,” explain the researchers.

“The malware accomplishes this via execution of regedit.exe.”

This tactic was observed by Guidepoint Security, which reports seeing repeated abuse of the rwdrv.sys driver in Akira ransomware attacks since July 15, 2025.

“We are flagging this behavior because of its ubiquity in recent Akira ransomware IR cases. This high-fidelity indicator can be used for proactive detection and retroactive threat hunting,” continued the report.

To help defenders detect and block these attacks, Guidepoint Security has provided a YARA rule for hlpdrv.sys, as well as complete indicators of compromise (IoCs) for both drivers, their service names, and file paths where they are dropped.

Akira attacks on SonicWall SSLVPN

Akira ransomware was recently linked to attacks on SonicWall VPNs using what is believed to be an unknown flaw.

Guidepoint Security says it could neither confirm nor debunk the exploitation of a zero-day vulnerability in SonicWall VPNs by Akira ransomware operators.

In response to reports about elevated offensive activity, SonicWall advised disabling or restricting SSLVPN, enforcing multi-factor authentication (MFA), enabling Botnet/Geo-IP protection, and removing unused accounts.

Meanwhile, The DFIR Report has published an analysis of recent Akira ransomware attacks, highlighting the use of the Bumblebee malware loader delivered via trojanized MSI installers of IT software tools.

An example involves searches for “ManageEngine OpManager” on Bing, where SEO poisoning redirected the victim to the malicious site opmanager[.]pro.

Malicious website starting an Akira attack
Malicious website starting an Akira attack
Source: The DFIR Report

Bumblebee is launched via DLL sideloading, and once C2 communication is established, it drops AdaptixC2 for persistent access.

The attackers then conduct internal reconnaissance, create privileged accounts, and exfiltrate data using FileZilla, while maintaining access via RustDesk and SSH tunnels.

After approximately 44 hours, the main Akira ransomware payload (locker.exe) is deployed to encrypt systems across domains.

Until the SonicWall VPN situation clears up, system administrators should monitor for Akira-related activity and apply filters and blocks as indicators emerge from security research.

It is also strongly advised to only download software from official sites and mirrors, as impersonation sites have become a common source for malware.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/feed/ 0 51872
DragonForce ransomware abuses SimpleHelp in MSP supply chain attack https://earlybirdsinvest.com/dragonforce-ransomware-abuses-simplehelp-in-msp-supply-chain-attack/ https://earlybirdsinvest.com/dragonforce-ransomware-abuses-simplehelp-in-msp-supply-chain-attack/#respond Wed, 28 May 2025 03:03:05 +0000 https://earlybirdsinvest.com/dragonforce-ransomware-abuses-simplehelp-in-msp-supply-chain-attack/

Network attacks

The DragonForce ransomware operation successfully breached a managed service provider and used its SimpleHelp remote monitoring and management (RMM) platform to steal data and deploy encryptors on downstream customers’ systems.

Sophos was brought in to investigate the attack and believe the threat actors exploited a chain of older SimpleHelp vulnerabilities tracked as CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726 to breach the system.

SimpleHelp is a commercial remote support and access tool commonly used by MSPs to manage systems and deploy software across customer networks. 

The report by Sophos says that the threat actors first used SimpleHelp to perform reconnaissance on customer systems, such as collecting information about the MSP’s customers, including device names and configuration, users, and network connections.

The threat actors then attempted to steal data and deploy decryptors on customer networks, which were blocked on one of the networks using Sophos endpoint protection. However, the other customers were not so lucky, with devices encrypted and data stolen for double-extortion attacks.

Sophos has shared IOCs related to this attack to help organizations better defend their networks.

MSPs have long been a valuable target for ransomware gangs, as a single breach can lead to attacks on multiple companies. Some ransomware affiliates have specialized in tools commonly used by MSPs, such as SimpleHelp, ConnectWise ScreenConnect, and Kaseya.

This has led to devastating attacks, including REvil’s massive ransomware attack on Kaseya, which impacted over 1,000 companies.

DragonForce gains notoriety following UK retail attacks

The DragonForce ransomware gang has recently surged in notoriety after being linked to a wave of high-profile retail breaches involving threat actors utilizing Scattered Spider tactics.

As first reported by BleepingComputer, the group’s ransomware was deployed in attacks on the United Kingdom retailer Marks & Spencer. Soon after, the same threat actors breached another UK retailer, Co-op, who confirmed a significant amount of customer data was stolen.

BleepingComputer previously reported that DragonForce is trying to build a “cartel” by offering a white-label ransomware-as-a-service (RaaS) model, allowing affiliates to deploy rebranded versions of its encryptor.

With its increasingly affiliate-friendly approach and growing list of victims, DragonForce is quickly becoming a major player in the ransomware landscape.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/dragonforce-ransomware-abuses-simplehelp-in-msp-supply-chain-attack/feed/ 0 38694