ThreatCluster

Hackers Exploit Security Driver to Disable Endpoint Protection for Ransomware Deployment

First seen 22 Jan 2026, 02:59 UTC GbhackersCybersecuritynews 55

Article Content

Browse articles
ThreatCluster

Hackers have weaponized over 2,500 variants of the truesight.sys security driver from Adlice Software's RogueKiller antivirus to disable endpoint protection mechanisms prior to launching ransomware attacks. This campaign exploits a critical vulnerability in the legacy version 2.0.2, allowing attackers to terminate processes via a specific IOCTL command.