HomeSecurityBlackByte ransomware: Uses the new BYOVD technique

BlackByte ransomware: Uses the new BYOVD technique

The BlackByte ransomware gang uses a new technique that researchers call “Bring Your Own Driver,” which allows bypassing protections by disabling more than 1,000 drivers used by various security solutions.

See also: Optus data breach: Man arrested for blackmailing company customers

BlackByte

Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.

Exploiting the security issue allowed BlackByte to disable drivers that prevent the proper functioning of multi-point detection and response (EDR) and antivirus products.

The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with elevated privileges on the system.

Two notable recent examples of BYOVD attacks include the Lazarus group's abuse of a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the game Genshin Impact.

See also: Avast: Decryption tool for Hades ransomware

Details of the attack

Security researchers at cybersecurity firm Sophos explain that the abused MSI graphics driver offers I/O control codes directly accessible by user-mode processes, which violates Microsoft's security guidelines for accessing kernel memory.

This enables attackers to read, write, or execute code in kernel memory without using shellcode or an exploit.

In the first stage of the attack, BlackByte determines the kernel version to select the correct offsets that match the kernel ID .

BlackByte ransomware: Uses the new BYOVD technique

RTCore64.sys is then dropped into “AppData\Roaming” and creates a service using a coded name and a randomly chosen, not-so-discreet display name.

BlackByte

Attackers then exploit the driver vulnerability to remove Kernel Notify Routines that correspond to security tool processes.

The retrieved callback addresses are used to extract the corresponding driver name and are compared against a list of 1,000 targeted drivers that support the operation of AV/EDR tools.

See also: Anonymous and other hacking groups help protesters in Iran with cyberattacks

Any matches found at this stage are removed by replacing the element containing the address of the callback function with zeros, thus invalidating the targeted driver.

BlackByte

Sophos also highlights several methods BlackByte uses in these attacks to evade analysis by security researchers, such as looking for signs of a debugger running on the system and exiting.

The BlackByte malware also checks for a list of linked DLLs used by Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security and terminates its execution if found.

System administrators can protect themselves from BlackByte's new security bypass trick by adding this particular MSI driver to an active block list.

Additionally, administrators should monitor all driver installation events and check them frequently to find any rogue drivers that do not have a hardware match.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS