• 3,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

News » Microsoft-approved hardware drivers used in cyber attacks

Microsoft-approved hardware drivers used in cyber attacks

Microsoft-approved hardware drivers used in cyber attacks

OXFORD, UNITED KINGDOM – Hardware drivers signed by Microsoft have been used in ransomware attacks according to information technology (IT) security company Sophos’ research arm. 

According to Sophos, a pair of files were found on compromised machines that Sophos says “work together to terminate processes or services used by a variety of endpoint security product vendors.”

“In our post-attack analysis, SophosLabs determined that the pair of executable files — a cryptographically signed Windows driver (signed with a legitimate signing certificate) and an executable “loader” application designed to install the driver — were used in tandem in a failed attempt to disable endpoint security tools on the targeted machines,” Sophos stated in a news release posted on its website. 

Sophos, together with two other IT security firms SentinelLabs and Mandiant spotted that the prominent threats were intruding telecommunication, business process outsourcing (BPO), managed security service providers (MSSP) and financial services companies.

The report made by Sophos noted that the use of device drivers to sabotage or terminate security tools has been increasing in 2022.

“The research by SophosLabs indicates that the threat actors are moving up the trust pyramid, attempting to use increasingly more well-trusted cryptographic keys to digitally sign their drivers,” according to Sophos.

Start your
journey today

  • Independent
  • Free
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO)

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between Philippines outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 350+ podcast episodes, and a comprehensive directory with 900+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
3,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 3,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 3,000 firms
  • Simple
  • Transparent
Banner Image