ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

BlackByte Ransomware Abuses Vulnerable Windows Driver to Disable Security Solutions

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-19320
Ring0 Memcpy Flaw in GIGABYTE GDrv Driver Enables Local Privilege Escalation

CVE-2018-19320 is a local privilege-escalation flaw in the GDrv (gdrv.sys) low-level Windows kernel driver shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (v2.08). The driver exposes an unchecked ring0 memcpy-like routine, so a low-privileged local process can have it copy attacker-controlled data into protected kernel memory. An attacker who exploits this gains complete control of the affected system at ring 0, enabling kernel-level code execution and the ability to disable security software, which ransomware operators such as RobbinHood and BlackByte have done by leveraging the vulnerable GIGABYTE driver. Any Windows system running one of the affected GIGABYTE utilities, or where the gdrv.sys driver those utilities install remains present, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use and is being actively exploited; EPSS estimates a 3.6% probability of exploitation within 30 days (89th percentile).

Do: Apply vendor updates per CISA's required action: upgrade to AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and current APP Center and OC GURU II releases, or uninstall the utilities entirely. Hunt endpoints for the gdrv.sys driver in the System32 drivers folder, since it can persist after the utility is removed, and prioritize patching systems where unprivileged users can invoke it, as ransomware operators actively load or exploit this driver to gain ring0 access and kill security software.

7.84% KEV ransomware PoC ×2
  • GIGABYTE APP Center v1.05.21 and earlier
  • GIGABYTE AORUS GRAPHICS ENGINE before 1.57
  • GIGABYTE XTREME GAMING ENGINE before 1.26
  • +1 more
mass≈1,000,000+ systems (bundled utilities from a top-tier motherboard/GPU vendor; no published install counts)
CVE-2019-16098
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/

The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

NVD description · AI analysis pending
7.820% PoC
  • msi afterburner
Full article328 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 07, 2022

In yet another case of bring your own vulnerable driver (BYOVD) attack, the operators of the BlackByte ransomware are leveraging a flaw in a legitimate Windows driver to bypass security solutions.

"The evasion technique supports disabling a whopping list of over 1,000 drivers on which security products rely to provide protection," Sophos threat researcher Andreas Klopsch said in a new technical write-up.

BYOVD is an attack technique that involves threat actors abusing vulnerabilities in legitimate, signed drivers to achieve successful kernel-mode exploitation and seize control of compromised machines.

Weaknesses in signed drivers have been increasingly co-opted by nation-state threat groups in recent years, including Slingshot, InvisiMole, APT28, and most recently, the Lazarus Group.

BlackByte, believed to be an offshoot of the now-discontinued Conti group, is part of the big game cybercrime crews, which zeroes in on large, high-profile targets as part of its ransomware-as-a-service (RaaS) scheme.

According to the cybersecurity firm, recent attacks mounted by the group have taken advantage of a privilege escalation and code execution flaw (CVE-2019-16098, CVSS score: 7.8) affecting the Micro-Star MSI Afterburner RTCore64.sys driver to disable security products.

What's more, an analysis of the ransomware sample has uncovered multiple similarities between the EDR bypass implementation and that of a C-based open source tool called EDRSandblast, which is designed to abuse vulnerable signed drivers to evade detection.

BlackByte is the latest ransomware family to embrace the BYOVD method to achieve its goals, after RobbinHood and AvosLocker, both of which have weaponized bugs in gdrv.sys (CVE-2018-19320) and asWarPot.sys to terminate processes associated with endpoint protection software.

To protect against BYOVD attacks, it's recommended to keep track of the drivers installed on the systems and ensure they are up-to-date, or opt to blocklist drivers known to be exploitable.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/10/blackbyte-ransomware-abuses-vulnerable.html