The BlackByte ransomware gang uses a new technique that researchers call “Bring Your Own Driver,” which allows bypassing protections by disabling more than 1,000 drivers used by various security solutions.
See also: Optus data breach: Man arrested for blackmailing company customers

Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.
Exploiting the security issue allowed BlackByte to disable drivers that prevent the proper functioning of multi-point detection and response (EDR) and antivirus products.
The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with elevated privileges on the system.
Two notable recent examples of BYOVD attacks include the Lazarus group's abuse of a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the game Genshin Impact.
See also: Avast: Decryption tool for Hades ransomware
Details of the attack
Security researchers at cybersecurity firm Sophos explain that the abused MSI graphics driver offers I/O control codes directly accessible by user-mode processes, which violates Microsoft's security guidelines for accessing kernel memory.
This enables attackers to read, write, or execute code in kernel memory without using shellcode or an exploit.
In the first stage of the attack, BlackByte determines the kernel version to select the correct offsets that match the kernel ID .

RTCore64.sys is then dropped into “AppData\Roaming” and creates a service using a coded name and a randomly chosen, not-so-discreet display name.

Attackers then exploit the driver vulnerability to remove Kernel Notify Routines that correspond to security tool processes.
The retrieved callback addresses are used to extract the corresponding driver name and are compared against a list of 1,000 targeted drivers that support the operation of AV/EDR tools.
See also: Anonymous and other hacking groups help protesters in Iran with cyberattacks
Any matches found at this stage are removed by replacing the element containing the address of the callback function with zeros, thus invalidating the targeted driver.

Sophos also highlights several methods BlackByte uses in these attacks to evade analysis by security researchers, such as looking for signs of a debugger running on the system and exiting.
The BlackByte malware also checks for a list of linked DLLs used by Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security and terminates its execution if found.
System administrators can protect themselves from BlackByte's new security bypass trick by adding this particular MSI driver to an active block list.
Additionally, administrators should monitor all driver installation events and check them frequently to find any rogue drivers that do not have a hardware match.
Information source: bleepingcomputer.com
