January 25TH REDSHORT — Scattered Spider’s Devious Web Custom Malware. Deploys a malicious kernel driver through a vulnerability (CVE-2015-2291) in the Intel Ethernet diagnostics driver. The activity exploits a well-known and pervasive deficiency in Windows security, enabling adversaries to bypass Windows kernel protections with the Bring-Your-Own-Vulnerable-Driver tactic.
Comments