Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Abusing Trust: Threat Actors Leverage Signed Drivers for Stealthy Windows Kernel Exploits

Cybercriminals continue to use kernel-level malware as a preferred weapon against Windows systems amid a terrifying increase in cyberthreats. Operating at ring 0 the highest privilege level in the operating system such malware grants attackers…

Cybercriminals continue to use kernel-level malware as a preferred weapon against Windows systems amid a terrifying increase in cyberthreats. Operating at ring 0 the highest privilege level in the operating system such malware grants attackers unparalleled access to disable security defenses, maintain persistence, and operate undetected. Despite Microsoft’s robust countermeasures like PatchGuard, Driver Signature Enforcement (DSE), and Hypervisor-Protected Code Integrity (HVCI), threat actors are exploiting digitally signed drivers and underground services to bypass these protections. Kernel-Level Malware Recent research by Group-IB Report, analyzing over 620 malicious drivers and 80+ compromised certificates since 2020, reveals a sophisticated ecosystem where attackers leverage legitimate trust mechanisms to execute stealthy, high-impact operations at the kernel level. The allure of kernel-level access lies in its ability to manage critical OS functions such as memory, threads, and hardware operations, making it an ideal entry point for bypassing antivirus and endpoint detection tools while altering system behavior without a trace. Attackers have adapted by abusing the Windows Hardware Compatibility Program (WHCP) and Extended Validation (EV) certificates to sign malicious kernel drivers, effectively masquerading as legitimate software. Source of Second Stage Kernel driver Underground Markets Fuel the Threat Landscape Group-IB’s investigation highlights a surge in such activity, with over 250 drivers and 34 certificates tied to malicious campaigns in 2022 alone, often linked to Chinese entities based on metadata analysis. Kernel loaders, acting as first-stage drivers, add another layer of obfuscation by dynamically loading unsigned or signed secondary drivers into memory, enhancing stealth and adaptability. Notable malware families like FiveSys and POORTRY used by ransomware groups such as Cuba and LockBit exploit these loaders to retrieve payloads from command-and-control servers or local storage, evading traditional detection mechanisms. Further deepening the concern is the thriving underground market for EV certificates and WHCP accounts, where vendors some likely Russian-speaking actors within Chinese cybercriminal communities sell these credentials for as little as $260 to $15,000. These certificates, often obtained through fraudulent business registrations or stolen identities, enable even less-skilled threat actors to deploy signed kernel malware capable of disabling security tools. Validation steps by CA The overlap in signing infrastructure across unrelated campaigns, such as RedDriver’s reuse in browser hijacking and persistence schemes, underscores a shared ecosystem of abuse. Since 2020, the preference for WHCP-signed drivers over standalone EV certificates has grown, reflecting attackers’ intent to exploit deeper trust within Microsoft’s ecosystem. The exploitation of legitimate processes like WHCP driver submission requiring only an EV certificate, enrollment in the Microsoft Partner Center, and a crash-free driver reveals critical vulnerabilities in the verification chain. While Certificate Authorities (CAs) enforce steps like legal and operational existence checks, limited human oversight, often restricted to a phone call, leaves room for well-resourced threat actors or nation-states to manipulate the system. The rise of kernel loaders and signed drivers calls for urgent reforms, including stricter certificate issuance with physical presence verification and enhanced collaboration between CAs, OS vendors, and the security community to revoke abused credentials swiftly. As cybercriminals continue to adapt, fortifying these trust mechanisms is paramount to safeguarding Windows systems from the stealthy, persistent threat of kernel-level exploits. Exclusive Webinar Alert: Harnessing Intel® Processor Innovations for Advanced API Security – Register for Free

Based on reporting by GBHackers.

Cybercriminals continue to use kernel-level malware as a preferred weapon against Windows systems amid a terrifying increase in cyberthreats.
Laura Mitchell · Thehackingpost
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories