ZeroHour
Security Affairspublished ()ingested @securityaffairs

RobbinHood ransomware exploit GIGABYTE driver flaw to kill security software

highRansomwareimportance 60CVE-2018-19320

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-19320
Ring0 Memcpy Flaw in GIGABYTE GDrv Driver Enables Local Privilege Escalation

CVE-2018-19320 is a local privilege-escalation flaw in the GDrv (gdrv.sys) low-level Windows kernel driver shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (v2.08). The driver exposes an unchecked ring0 memcpy-like routine, so a low-privileged local process can have it copy attacker-controlled data into protected kernel memory. An attacker who exploits this gains complete control of the affected system at ring 0, enabling kernel-level code execution and the ability to disable security software, which ransomware operators such as RobbinHood and BlackByte have done by leveraging the vulnerable GIGABYTE driver. Any Windows system running one of the affected GIGABYTE utilities, or where the gdrv.sys driver those utilities install remains present, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use and is being actively exploited; EPSS estimates a 3.6% probability of exploitation within 30 days (89th percentile).

Do: Apply vendor updates per CISA's required action: upgrade to AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and current APP Center and OC GURU II releases, or uninstall the utilities entirely. Hunt endpoints for the gdrv.sys driver in the System32 drivers folder, since it can persist after the utility is removed, and prioritize patching systems where unprivileged users can invoke it, as ransomware operators actively load or exploit this driver to gain ring0 access and kill security software.

7.84% KEV ransomware PoC ×2
  • GIGABYTE APP Center v1.05.21 and earlier
  • GIGABYTE AORUS GRAPHICS ENGINE before 1.57
  • GIGABYTE XTREME GAMING ENGINE before 1.26
  • +1 more
mass≈1,000,000+ systems (bundled utilities from a top-tier motherboard/GPU vendor; no published install counts)
Full article483 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 08, 2020

The operators behind the infamous RobbinHood ransomware are exploiting a vulnerable GIGABYTE driver to kill antivirus products.

Cybercriminals behind the RobbinHood Ransomware are exploiting a vulnerable GIGABYTE driver to install a malicious and unsigned driver into Windows with the intent of disabling security products.

Ransomware operators leverage a custom antivirus killing package that is delivered to workstations to disable security solution before starting encryption.

Normally, Windows security software processes could only be killed by Kernel drivers. In order to prevent the abuse of kernel drivers, Microsoft also implements a driver signature verification mechanism, this means that only kernel drivers co-signed by Microsoft could be installed.

Now security researchers from Sophos have detailed a new novel technique implemented by threat actors in attacks ([12]) involving two pieces of RobbinHood ransomware.

robbinhood ransomware

Attackers installed a known vulnerable GIGABYTE driver that has been cosigned by Microsoft and exploited a known vulnerability to disable Microsoft’s driver signature enforcement feature.

“Sophos has been investigating two different ransomware attacks where the adversaries deployed a legitimate, digitally signed hardware driver in order to delete security products from the targeted computers just prior to performing the destructive file encryption portion of the attack.” reads the report published by Sophos. “The signed driver, part of a now-deprecated software package published by Taiwan-based motherboard manufacturer Gigabyte, has a known vulnerability, tracked as CVE-2018-19320.”

The technique used by the operators consists in:

  1. Attackers get a foothold on the target’s network and install legitimate Gigabyte kernel driver GDRV.SYS.
  2. Attackers exploit the CVE-2018-19320 vulnerability in the legitimate driver to gain kernel access.
  3. Attackers use the kernel access to temporarily disable the Windows OS driver signature enforcement and install a malicious kernel driver named RBNL.SYS.
  4. Attackers use this driver to disable security products.
  5. Attackers execute the RobbinHood ransomware and attempt to encrypt the files on the infected host.

“In this attack scenario, the criminals have used the Gigabyte driver as a wedge so they could load a second, unsigned driver into Windows,” continues the Sophos’ report. “This second driver then goes to great lengths to kill processes and files belonging to endpoint security products, bypassing tamper protection, to enable the ransomware to attack without interference.”

In the attacks observed by Sophos, the operators deployed an executable named Steel.exe that exploit the CORE-2018-0007 vulnerability in the GIGABYTE gdrv.sys driver.

Experts pointed out that the Steel.exe program terminates processes whose files are included in a file called PLIST.TXT, unfortunately Sophos had mo access to the file and it is not able to determine what security solutions are being targeted.

Once the Steel.exe has terminated security software, the RobbinHood ransomware will encrypt files on the infected systems.

Technical details about the attacks are reported in the report published by Sophos, including Indicators of Compromise (IoCs).

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – RobbinHood ransomware, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/97457/malware/robbinhood-ransomware-gigabyte-driver.html