Ransomware Exploits GIGABYTE Driver to Kill AV Processes

[correlate]

Level 18
Thread author
Verified
Top Poster
Well-known
Forum Veteran
May 4, 2019
791
9,574
1,670
New York
The attackers behind the RobbinHood Ransomware are exploiting a vulnerable GIGABYTE driver to install a malicious and unsigned driver into Windows that is used to terminate antivirus and security software.

When performing a network-wide compromise, ransomware attackers need to push out a ransomware executable as quickly as possible and to as many systems as they can to avoid being detected.

One protection that can get in their way of a successful attack, though, is antivirus software running on a workstation that removes the ransomware executable before it can be executed.
Ransomware Exploits GIGABYTE Driver to Kill AV Processes
 
Last 3 IOC still have no or low detection on VT.
 
Last 3 IOC still have no or low detection on VT.

I don't know if you recognized one of the authors.
Mark Loman, one of the Loman brothers who developed HitmanPA and HP.(y);)
This malware is also not designed to run with W.XP.