Over 2,500 Truesight.sys Driver Versions Being Exploited to Circumvent EDR and Install HiddenGh0st RAT
Researchers have identified a widespread malware operation that is utilizing an insecure Windows driver linked to Adlice’s software collection to avoid detection mechanisms and distribute the Gh0st RAT malicious software.
“In order to elude detection even more effectively, the hackers intentionally created numerous versions (with diverse hashes) of the 2.0.2 driver by altering certain PE components while maintaining the integrity of the signature,” according to Check Point
“In order to elude detection even more effectively, the hackers intentionally created numerous versions (with diverse hashes) of the 2.0.2 driver by altering certain PE components while maintaining the integrity of the signature,” according to Check Point
