Skip to content
ThreatCluster

Hackers Exploit Security Driver to Disable Endpoint Protection for Ransomware Deployment

First seen 22 Jan 2026, 02:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Hackers have weaponized over 2,500 variants of the truesight.sys security driver from Adlice Software's RogueKiller antivirus to disable endpoint protection mechanisms prior to launching ransomware attacks. This campaign exploits a critical vulnerability in the legacy version 2.0.2, allowing attackers to terminate processes via a specific IOCTL command.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)