Hackers can bypass Microsoft Defender to install ransomware on PCs
mediastack
2025-08-07 15:00
Hackers can bypass Microsoft Defender to install ransomware on PCs
In a report published by security company GuidePoint Security, they’ve issued a warning that hackers can effectively bypass Microsoft Defender to install and deploy Akira ransomware.This is done by exploiting a vulnerable driver called rwdrv.sys, which is a legitimate driver used by an Intel CPU tuning tool called ThrottleStop. By exploiting this driver, a hacker can gain kernel-level access to the PC.With kernel-level access, the hacker can then load their own malicious driver—in this case, hlpdrv.sys, which modifies the Windows Registry and causes Microsoft Defender to disable its...

https://www.pcworld.com/article/2871304/hackers-can-bypass-microsoft-defender-to-install-ransomware-on-pcs.html

#pcworld
Göm kommentarerna Kommentarer (0)

Du måste logga in före du kommenterar