A ransomware gang is installing vulnerable GIGABYTE drivers on computers it wants to infect. The purpose of these drivers is to allow hackers to disable security productsso that their ransomware strain can encrypt files without being detected or stopped.
This new, original technique has been detected in two ransomware episodes so far, according to Sophos.
In both cases, the ransomware was RobbinHood, a “big game” ransomware strain typically used in targeted attacks against selected high-value targets.
In a published report, Sophos describes this new technique as follows:
- Hackers install the legitimate Gigabyte kernel driver GDRV.SYS.
- Hackers exploit a vulnerability in this driver to gain access to the kernel.
- Attackers use kernel access to temporarily disable the Windows OS's driver signature enforcement program.
- Hackers install a malicious kernel driver program called RBNL.SYS.
- Attackers use this driver program to disable or stop antivirus programs and other security products running on an infected host.
- Hackers execute the RobbinHood ransomware and encrypt the victim's files.
Sophos reports that this antivirus works on Windows 7, Windows 8, and Windows 10.

This technique is successful because of the way the vulnerability is handled in the Gigabyte driver, leaving a loophole that hackers.
For this disappointment, two parties are to blame – first Gigabyte, and then Verisign.
Gigabyte's fault lies in the unprofessional way it handled the vulnerability report for the affected driver. Instead of acknowledging the problem and releasing a patch, Gigabyte claimed that its products were not affected.
The company's blatant refusal to acknowledge the vulnerability led the researchers who found the bug to publicly release details about the bug, along with proof-of-concept code to reproduce the vulnerability. The release of the code gave attackers a roadmap for exploiting the Gigabyte driver.
When public pressure was put on the company to fix the driver, Gigabyte chose to discontinue its operation rather than release a patch.
But even if Gigabyte had released a patch, attackers could simply use an older vulnerable version of the driver. In that case, the driver's signing certificate would have been revoked, so older versions of the driver would not be able to load.
“Verisign, whose code signing mechanism was used to digitally sign the driver, has not revoked the signing certificate, so the Authenticode signature remains valid,” Sophos researchers said, explaining why it was still possible to load a previously deprecated and known vulnerable driver into Windows.
But if we've learned anything about cybercriminals, it's that most of them copy successful techniques, so other ransomware gangs are expected to incorporate this trick into their arsenals, leading to more attacks.
