Over 2,500 Truesight.sys Driver Versions Being Exploited to Circumvent EDR and Install HiddenGh0st RAT

Researchers have identified a widespread malware operation that is utilizing an insecure Windows driver linked to Adlice’s software collection to avoid detection mechanisms and distribute the Gh0st RAT malicious software.

Researchers have identified a widespread malware operation that is utilizing an insecure Windows driver linked to Adlice’s software collection to avoid detection mechanisms and distribute the Gh0st RAT malicious software.
“In order to elude detection even more effectively, the hackers intentionally created numerous versions (with diverse hashes) of the 2.0.2 driver by altering certain PE components while maintaining the integrity of the signature,” according to Check Point

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.