The threat actors have been observed utilizing Microsoft's Sysinternals PsExec command-line utility to execute a malicious batch script, which checks for the existence of a process named "Martini.exe," and if found, terminates it ensure there is only one instance of the process running the machine.
The executable's main responsibility is to download and run the "Martini.sys" driver from a remote server in order to disable 991 security tools.
It's worth noting that "Martini.sys" is a legitimate signed driver named "viragt64.sys" that has been added to Microsoft's vulnerable driver blocklist.
"If Martini.sys does not exist, the malware will terminate itself and not proceed with its intended routine," the researchers said, indicating the crucial role played by the driver in defense evasion.