The ALPHV ransomware group (also known as BlackCat) was observed to use signed, malicious Windows kernel drivers to evade detection by security software during attacks.
See also: Emotet: Used by the Quantum and BlackCat ransomware gangs

The driver detected by Trend Micro is an improved version of the malware called “POORTRY,” which Microsoft, Mandiant, Sophos, and SentinelOne had detected in ransomware attacks late last year.
The POORTRY malware is a Windows kernel driver that is signed using stolen keys belonging to legitimate accounts in Microsoft's Windows Hardware Development Program.
This malicious driver, used by the hacking group UNC3944 (also known as 0ktapus and Scattered Spider), was used to terminate security software running on a Windows device in order to evade detection.
See also: BlackCat ransomware data exfiltration tool gets upgraded
While security software is usually protected from termination or corruption, since Windows kernel drivers run with the highest privileges in the operating system, they can be used to terminate almost any process.
Trend Micro said that the ransomware operators attempted to use the Microsoft-signed POORTRY driver, but due to the publicity it received and the subsequent revocation of the code signing keys, its detection rates were high.
Therefore, the hackers used an updated version of the POORTRY kernel driver, signed using a stolen or leaked cross-signature certificate.
The new driver used by the BlackCat ransomware operation helps it elevate its privileges on infected machines and then terminate processes related to security agents.
Additionally, it may provide a loose connection between the ransomware gang and the UNC3944/Scattered Spider hacking group.
See also: ALPHV BlackCat: Clones victim's site for data leak
The malicious Windows kernel driver
The signed driver detected by Trend Micro in the February 2023 BlackCat attacks is “ktgn.sys”, which was placed on the victim’s file system in the %Temp% folder and then loaded by a user program named “tjr.exe”
Analysts say that the digital signature of ktgn.sys has been revoked - however, the driver still loads without issue on 64-bit Windows systems with enforced signing policies.
The malicious kernel driver exposes an IOCTL interface, allowing the user mode client, tjr.exe, to issue commands that the driver will execute with Windows kernel privileges.

Trend Micro analysts observed the following exposed commands that can be issued to the driver:
- Driver activation
- Deactivating the driver after the user mode client completes the operation
- Kill every user-mode process
- Delete specific file paths
- Forcibly deleting a file by releasing its handles and terminating running processes using
- Copy files
- Forced copying of files using a similar mechanism to force-delete
- Registering Process/Thread Notification calls
- Unregister Process/Thread Notification callbacks
- Reboot the system by calling the 'HalReturnToFirmware' API
Trend Micro comments that the two commands used for Process/Thread Notification callbacks do not work, which suggests that the driver is under development or still in the testing phase.
System administrators are advised to use the indicators of compromise shared by Trend Micro and add the malicious drivers used by ransomware carriers to the Windows driver exclusion list.
Windows administrators should also ensure that the “Driver Signature Enforcement” feature is enabled, which prevents the installation of any driver that does not have a valid digital signature.
Information source: bleepingcomputer.com
