logoalt Hacker News

bri3dtoday at 3:46 AM1 replyview on HN

This is a great writeup.

It looks like this driver is being actively used in malware, too: https://www.fortinet.com/blog/threat-research/interlock-rans...


Replies

svespalectoday at 3:54 AM

Thanks! I had no idea it was already being used in the wild. It's a good case study for why shipping signed drivers with exposed IOCTLs and weak authentication is such a liability, even if (especially if) the developer never bothers to even load them.