Hackers Exploit Security Driver to Disable Endpoint Protection for Ransomware Deployment
First seen 22 Jan 2026, 02:59 UTC
•
•55
Export
Article Content
Browse articles
Hackers have weaponized over 2,500 variants of the truesight.sys security driver from Adlice Software's RogueKiller antivirus to disable endpoint protection mechanisms prior to launching ransomware attacks. This campaign exploits a critical vulnerability in the legacy version 2.0.2, allowing attackers to terminate processes via a specific IOCTL command.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows