$4.99/mo - Save 61% With Exclusive 2-Year Plan + 4 Months Free!Claim Now

Kaspersky Labs Blocks Over 11,000 Info-Stealing Attempts Using BYOVD Technique

  • Last updated November 8, 2024
  • written by
    Writer

November 8, 2024 – Kaspersky Labs has reported the blocking of more than 11,000 attempts to steal information from Windows systems utilizing the bring your own vulnerable driver (BYOVD) technique. The attacks were detected over the past three months and spanned multiple countries including Russia, China, India, Brazil, and Mexico.

The BYOVD technique has emerged as a method for threat actors to extract sensitive data such as browser information, software details, and credit card data from victims’ systems. Kaspersky’s Global Research and Analysis Team (GReAT) identified a new malware variant named SteelFox, which combines info-stealing capabilities with crypto-mining functions.

The SteelFox malware was found to be distributed through forums and torrent trackers, masquerading as free activation cracks for popular software products like Foxit PDF Editor and AutoCAD. This malware not only delivers the promised functionality but also installs sophisticated malicious software on the user’s computer.

Kaspersky highlighted that the execution of the SteelFox malware begins with an executable file that requests administrator access, which is later exploited for malicious purposes. The malware can gather extensive information from the infected system, including cookies, credit card information, browsing history, and details about installed software and antivirus solutions.

Additionally, the SteelFox payload utilizes a vulnerable driver to escalate privileges, allowing it to create a Windows service that runs a file known as WinRingo.sys. This driver grants the highest level of access to the local system and is also part of the malware’s crypto-mining module.

The use of BYOVD for privilege escalation is more commonly associated with nation-state actors and ransomware groups, making its application in info-stealer attacks noteworthy. Microsoft has previously indicated that it aims to enhance kernel security by blocking drivers with known vulnerabilities on Windows 10 devices, particularly for those with Hypervisor-Protected Code Integrity enabled.

Kaspersky Labs’ findings underscore the evolving tactics of cybercriminals and the importance of robust cybersecurity measures to protect against such sophisticated threats.