Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Meta is secretly working on an AI detection tool after unleashing AI slop avalanche

    March 16, 2026

    This Alien Planet Might Be the Stinkiest Place in the Galaxy

    March 16, 2026

    Amazon is clearing out these popular DeWalt power tools by up to $190 off

    March 16, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»This devious ransomware is able to hijack your system to turn off Microsoft Defender
    Tech News

    This devious ransomware is able to hijack your system to turn off Microsoft Defender

    Michael ComaousBy Michael ComaousAugust 7, 20252 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    ransomware avast
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    • Experts warn Akira is using SonicWall VPNs to deploy two drivers
    • One is a legitimate, vulnerable driver that allows the other one to be executed
    • The other one disables antivirus and endpoint protection tools

    Akira ransomware has dominated the headlines recently due to its abuse of SonicWall SSL VPNs to gain initial access and deploy an encryptor.

    However, while initial access is important, it is still not enough to infect a device, especially if it’s protected by an antivirus, or an endpoint protection and response solution (EDR).

    Now, security researchers from Guidepoint Security believe they have seen exactly how Akira disables security solutions, which allows them to drop the ransomware.


    You may like

    A handful of targets

    In a recent report, researchers from Guidepoint outlined how Akira is engaged in a bring-your-own-vulnerable-driver (BYOD) attack, using the initial access to drop two drivers, one of which is legitimate.

    “The first driver, rwdrv.sys, is a legitimate driver for ThrottleStop. This Windows-based performance tuning and monitoring utility is primarily designed for Intel CPUs,” the researchers explained. “It is often used to override CPU throttling mechanisms, improve performance, and monitor processor behavior in real time.”

    The second driver, hlpdrv.sys is registered as a service but when executed, it modifies the DisableAntiSpyware settings of Windows Defender within the system registry.

    “We assess that the legitimate rwdrv.sys driver may be used to enable the execution of the malicious hlpdrv.sys driver, though we have been unable to reproduce the exact mechanism of action at this time,” the experts said.

    Multiple researchers have observed attacks coming from SonicWall SSL VPN’s, and since some of the instances were fully patched, they have speculated the threat actors could be exploiting a zero-day vulnerability.

    However, in a statement shared with TechRadar Pro, SonicWall said that the criminals were actually exploiting an n-day vulnerability.

    “Based on current findings, we have high confidence that this activity is related to CVE-2024-40766, which was previously disclosed and documented in our public advisory SNWLID-2024-0015, not a new zero-day or unknown vulnerability,” the company said.

    “The affected population is small, fewer than 40 confirmed cases, and appears to be linked to legacy credential use during migrations from Gen 6 to Gen 7 firewalls. We’ve issued updated guidance, including steps to change credentials and upgrade to SonicOS 7.3.0, which includes enhanced MFA protections.”

    Via BleepingComputer

    You might also like

    Defender devious hijack Microsoft ransomware system turn
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleIn Google’s quest to secure Android, it may have just broken fast charging
    Next Article The Framework Desktop made me fall for small form factor PCs
    Michael Comaous
    • Website

    Michael Comaous is a dedicated professional with a passion for technology, innovation, and creative problem-solving. Over the years, he has built experience across multiple industries, combining strategic thinking with hands-on expertise to deliver meaningful results. Michael is known for his curiosity, attention to detail, and ability to explain complex topics in a clear and approachable way. Whether he’s working on new projects, writing, or collaborating with others, he brings energy and a forward-thinking mindset to everything he does.

    Related Posts

    2 Mins Read

    Meta is secretly working on an AI detection tool after unleashing AI slop avalanche

    4 Mins Read

    This Alien Planet Might Be the Stinkiest Place in the Galaxy

    1 Min Read

    Amazon is clearing out these popular DeWalt power tools by up to $190 off

    1 Min Read

    WIRED Article Production automation page/Only for QA/Do not click/Do not publish

    2 Mins Read

    Apple’s AirPods Max 2 bring H2 chip, boosted ANC in April for $549

    3 Mins Read

    Antonio Gracias says he’s longing for ‘proentropic’ startups — those that are built to survive chaos

    Top Posts

    Discord will require a face scan or ID for full access next month

    February 9, 2026762 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025624 Views

    Trade in your old phone and get up to $1,100 off a new iPhone 17 at AT&T – here’s how

    September 10, 2025311 Views
    Stay In Touch
    • Facebook

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Discord will require a face scan or ID for full access next month

    February 9, 2026762 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025624 Views

    Trade in your old phone and get up to $1,100 off a new iPhone 17 at AT&T – here’s how

    September 10, 2025311 Views
    Our Picks

    Meta is secretly working on an AI detection tool after unleashing AI slop avalanche

    March 16, 2026

    This Alien Planet Might Be the Stinkiest Place in the Galaxy

    March 16, 2026

    Amazon is clearing out these popular DeWalt power tools by up to $190 off

    March 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 GeekBlog

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.