HomeSecurityHackers abuse Avast anti-rootkit driver and disable defenses

Hackers abuse Avast anti-rootkit driver and disable defenses

A new malicious campaign uses a legitimate but old and vulnerable Avast Anti-Rootkit driver programto evade detection and take control of the target system by disabling security components.

See also: FTC: Will prohibit Avast from selling browsing data for advertising purposes

Avast anti-rootkit

The malware affecting the driver program is a variant of an AV Killer. It comes with a coded list of 142 names for security procedures from various vendors.

Since Avast Anti-Rootkit can operate at the kernel level, it provides access to critical parts of the operating system and allows malware to terminate processes.

Security researchers at cybersecurity firm Trellix recently discovered a new attack that leverages the "bring-your-own-vulnerable-driver" (BYOVD) approach with an old version of the anti-rootkit driver to stop security products on a targeted system.

They explain that a piece of malware with the filename kill-floor.exe drops the vulnerable driver program with the filename ntfs.bin into the default Windows user folder. The malware then creates the service “aswArPot.sys” using Service Control (sc.exe) and registers the driver program.

See also: Avast: Decryption tool for DoNex, Muse, DarkRace ransomware

Then, the malware uses an encoded list of 142 processes related to security tools and checks it against multiple snapshots of active processes on the system.

Hackers abuse Avast anti-rootkit driver and disable defenses

Trellix researcher Trishaan Kalrasays that when it finds a match, “the malware creates a handle to reference the installed Avast driver.” It then leverages the “DeviceIoControl” API to issue the required IOCTL commands to terminate it.

With the defenses disabled, the malware can carry out malicious activities without triggering notifications to the user or being blocked.

In the field of cybersecurity, a critical concern is protecting systems from attacks that exploit vulnerable drivers. Driver programs serve as fundamental components, facilitating communication between the operating system and hardware devices. However, they can become weak points if not managed properly or not updated, as in the case of Avast Anti-Rootkit.

See also: Bug in Mallox Ransomware allows victims to recover files without paying ransom

To protect against these threats, it is crucial to implement multiple protective measures. Regularly updating drivers ensures that any known vulnerabilities are patched, reducing the risk of exploitation. Additionally, enabling System Guard or similar protections can help prevent unauthorized changes to critical parts of the system. Using reliable antivirus software and regularly scanning for malware can also identify potential threats before they can cause harm. By staying up-to-date on new vulnerabilities and maintaining a proactive security posture, organizations can significantly reduce the likelihood of successful attacks via vulnerable drivers.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS