Target Industry
Indiscriminate, opportunistic targeting.
Overview
Researchers at Check Point Research (CPR) have uncovered a large-scale cyber–attack campaign exploiting a vulnerable Windows driver from Adlice’s product suite. The attackers are using an outdated version of the Truesight.sys driver to bypass Windows security mechanisms and deploy malware.
Impact
Threat actors have used over 2,500 modified Truesight.sys drivers from Adlice’s product suite to disable endpoint detection and response (EDR) and antivirus (AV) solutions. The ultimate goal was to deploy the remote access trojan (RAT) malware, which can be used for remote control, data theft, and surveillance.
Exploitation
Threat actors have exploited a loophole in Windows driver signing policy, allowing legacy drivers signed before July 2015 to load on modern systems and bypass Microsoft’s Driver Signature Enforcement. They distributed malware disguised as legitimate applications through deceptive websites and messaging apps, ultimately installing the legacy driver and facilitating the deployment of the Gh0st RAT malware.
Gh0st RAT is a sophisticated RAT that enables attackers to gain full control over an infected computer, allowing them to monitor user activity, capture keystrokes, steal sensitive data, and execute commands remotely. The threat actors also modified the driver’s Portable Executable (PE) file structure to evade hash-based detection and employed commercial protectors like VMProtect to hinder reverse engineering.
Containment, Mitigations & Remediations
In December 2024 the Microsoft Security Response Center (MSRC) updated the Microsoft Vulnerable Driver Blocklist to included Truesight v2.0.2. This update prevents the vulnerable legacy drivers from being exploited in future attacks.
Threat Landscape
Darkside and TrueSightKiller have found a Proof of Concept (PoC) for this exploit. It was created to demonstrate how this vulnerability can be used maliciously. The PoC exploit has been publicly available since at least November 2023, showing that the vulnerability can be weaponised to terminate processes on a system, potentially leading to security breaches. The campaign primarily targeted systems in China, with additional victims in Singapore and Taiwan.
Threat Group
CPR believes there is a medium to high chance that the threat group behind this attack could be linked to Silver Fox. Silver Fox is a cybercriminal group believed to be based in China. They have been involved in various malicious activities, primarily targeting the healthcare sector. They are known for exploiting legitimate medical software, and their attacks often involve installing the ValleyRAT.
Silver Fox uses techniques like phishing and SEO poisoning to distribute their malware. They also employ tools like TrueSightKiller to disable antivirus and endpoint detection and response (EDR) systems, making their attacks more effective.
Further Information













