Target Industry

Indiscriminate, opportunistic targeting. 

Overview

Researchers at Check Point Research (CPR) have uncovered a large-scale cyberattack campaign exploiting a vulnerable Windows driver from Adlice’s product suite. The attackers are using an outdated version of the Truesight.sys driver to bypass Windows security mechanisms and deploy malware.  

Impact

Threat actors have used over 2,500 modified Truesight.sys drivers from Adlice’s product suite to disable endpoint detection and response (EDR) and antivirus (AV) solutions.  The ultimate goal was to deploy the remote access trojan (RAT) malware, which can be used for remote control, data theft, and surveillance.   

Exploitation

Threat actors have exploited a loophole in Windows driver signing policy, allowing legacy drivers signed before July 2015 to load on modern systems and bypass Microsoft’s Driver Signature Enforcement. They distributed malware disguised as legitimate applications through deceptive websites and messaging apps, ultimately installing the legacy driver and facilitating the deployment of the Gh0st RAT malware. 

Gh0st RAT is a sophisticated RAT that enables attackers to gain full control over an infected computer, allowing them to monitor user activity, capture keystrokes, steal sensitive data, and execute commands remotely. The threat actors also modified the driver’s Portable Executable (PE) file structure to evade hash-based detection and employed commercial protectors like VMProtect to hinder reverse engineering. 

Containment, Mitigations & Remediations

In December 2024 the Microsoft Security Response Center (MSRC)  updated the Microsoft Vulnerable Driver Blocklist to includedTruesight v2.0.2. This update prevents the vulnerable legacy drivers from being exploited in future attacks.  

Threat Landscape

Darkside and TrueSightKiller have found a Proof of Concept (PoC) for this exploit. It was created to demonstrate how this vulnerability can be used maliciously. The PoC exploit has been publicly available since at least November 2023, showing that the vulnerability can be weaponised to terminate processes on a system, potentially leading to security breaches. The campaign primarily targeted systems in China, with additional victims in Singapore and Taiwan. 

Threat Group

CPR believes there is a medium to high chance that the threat group behind this attack could be linked to Silver Fox. Silver Fox is a cybercriminal group believed to be based in China. They have been involved in various malicious activities, primarily targeting the healthcare sector. They are known for exploiting legitimate medical software, and their attacks often involve installing the ValleyRAT. 

 

Silver Fox uses techniques like phishing and SEO poisoning to distribute their malware. They also employ tools like TrueSightKiller to disable antivirus and endpoint detection and response (EDR) systems, making their attacks more effective. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content