Complex Mathematics

New malware exploits trusted Windows drivers to get around security systems – here’s how to stay safe




  • Chinese threat group abused a vulnerable WatchDog Antimalware driver to disable antivirus and EDR tools
  • Attackers also leveraged a Zemana Anti-Malware driver (ZAM.exe) for broader compatibility across Windows
  • Researchers are urging IT teams to update blocklists, use YARA rules, and monitor for suspicious activity

Chinese hackers Silver Fox have been seen abusing a previously trusted Windows driver to disable antivirus protections and deploy malware on target devices.

The latest driver to be abused in the age-old “Bring Your Own Vulnerable Driver” attack is called WatchDog Antimalware, usually part of the security solution of the same name.



Source link