The News Chronicle
  • About Us
  • Advert Rates
  • Contact Us
  • Privacy Policy
Friday, March 24, 2023
Advertisement
ADVERTISEMENT
  • News
    • Breaking
    • Business
    • Celebs
    • Sports
    • Africa
    • Technology
    • World News
  • Social Diary
    • Events
  • Columns
    • Monday
    • Tuesday
    • Wednesday
    • Thursday
    • Friday
    • Sunday
    • Opinions
    • Editorial: Our Stand
  • TNC TV
  • Interviews
  • Books
    • Reviews
    • Author Profiles
  • Entertainment
  • Gossip
No Result
View All Result
  • News
    • Breaking
    • Business
    • Celebs
    • Sports
    • Africa
    • Technology
    • World News
  • Social Diary
    • Events
  • Columns
    • Monday
    • Tuesday
    • Wednesday
    • Thursday
    • Friday
    • Sunday
    • Opinions
    • Editorial: Our Stand
  • TNC TV
  • Interviews
  • Books
    • Reviews
    • Author Profiles
  • Entertainment
  • Gossip
No Result
View All Result
The News Chronicle
No Result
View All Result
  • News
  • Social Diary
  • Columns
  • TNC TV
  • Interviews
  • Books
  • Entertainment

Path Naija News » News » Blackbyte Ransomware Abuses Legit Driver to Disable Security Products – NCC-CSIRT

Blackbyte Ransomware Abuses Legit Driver to Disable Security Products – NCC-CSIRT

Francis Francis by Francis Francis
6 months ago
in News, Technology
Reading Time: 2 mins read
A A
0
ADVERTISEMENT
Share on FacebookShare on TwitterShare on Whatsapp

The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has flagged a high-impact threat to Windows operating system, the Blackbyte Ransomware, which has the capacity to bypass protections by disabling more than 1,000 drivers used by various security solutions.

The NCC-CSIRT said the BlackByte ransomware gang, which is using a new technique that researchers called, “Bring Your Own Vulnerable Driver,” is exploiting the security issue that allowed it to disable drivers that prevent multiple Endpoint Detection and Response (EDR) and antivirus products like Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security, from operating normally.

RelatedPosts

Ohaneze Ndigbo Likens Unwarranted Attacks on Igbos in Lagos to Pre-Civil War Occurrences

Ohaneze Ndigbo Likens Unwarranted Attacks on Igbos in Lagos to Pre-Civil War Occurrences

March 24, 2023
Due To A Financial Crisis, Gas Prices Increased By 54.76% In February

Due To A Financial Crisis, Gas Prices Increased By 54.76% In February

March 24, 2023
CBN Loan

ABP And Other Actions See New CBN Payments Totaling N39.36 Billion

March 24, 2023

Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.

The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with high privileges on the system.

Two notable recent examples of BYOVD attacks include Lazarus, abusing a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the Genshin Impact game.

The NCC-CSIRT advisory recommended that system administrators protect against BlackByte’s new security bypassing trick by adding the particular MSI driver to an active blocklist, monitoring all driver installation events, and scrutinising them frequently to find any rogue injections that do not have a hardware match.

The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

The CSIRT also works collaboratively with the Nigeria Computer Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.

Tags: NCCRansomware
Plugin Install : Subscribe Push Notification need OneSignal plugin to be installed.
Previous Post

Atiku Mourns Prince Vincent Ogbulafor

Next Post

In All Things, Give Thanks

Francis Francis

Francis Francis

Related Posts

Ohaneze Ndigbo Likens Unwarranted Attacks on Igbos in Lagos to Pre-Civil War Occurrences

Ohaneze Ndigbo Likens Unwarranted Attacks on Igbos in Lagos to Pre-Civil War Occurrences

March 24, 2023
Due To A Financial Crisis, Gas Prices Increased By 54.76% In February

Due To A Financial Crisis, Gas Prices Increased By 54.76% In February

March 24, 2023
CBN Loan

ABP And Other Actions See New CBN Payments Totaling N39.36 Billion

March 24, 2023
Concerns As N3.6 Billion In Fraud Is Reported Through ATMs, PoS, And Mobile Channels

Concerns As N3.6 Billion In Fraud Is Reported Through ATMs, PoS, And Mobile Channels

March 24, 2023
Outstanding Allowances

NSCDC Vows Commitment to Protecting Schools Across Nigeria

March 24, 2023
We Need Someone Like You As Our Governor, Otuaro Tells Oborevwori 

We Need Someone Like You As Our Governor, Otuaro Tells Oborevwori 

March 24, 2023
Next Post
Nigeria: Between the President and the Presidency

In All Things, Give Thanks

ADVERTISEMENT

What's New?

Ohaneze Ndigbo Likens Unwarranted Attacks on Igbos in Lagos to Pre-Civil War Occurrences
News

Ohaneze Ndigbo Likens Unwarranted Attacks on Igbos in Lagos to Pre-Civil War Occurrences

by Kenechukwu Ofomah
March 24, 2023
0

The continued attacks, harassment and intimidation Igbos suffer in many parts of the country, especially in Lagos, has been likened...

Read more
Due To A Financial Crisis, Gas Prices Increased By 54.76% In February

Due To A Financial Crisis, Gas Prices Increased By 54.76% In February

March 24, 2023
CBN Loan

ABP And Other Actions See New CBN Payments Totaling N39.36 Billion

March 24, 2023
Prev Next
ADVERTISEMENT
ADVERTISEMENT
  • © 2022 The News Chronicle