Report: Hackers Bypass Microsoft Defender to Deploy Ransomware on Computers.
Windows users may want to consider enhancing their antivirus software to protect against emerging threats. While Microsoft Defender offers a basic layer of defense against ransomware, a recent report indicates that some hackers have discovered methods to bypass this protection, leading to potential ransomware infections on PCs.
A report from GuidePoint Security highlights that hackers are employing Akira ransomware to exploit a legitimate PC driver, enabling them to load a second, malicious driver that disables Windows Defender, which could lead to various security issues.
The legitimate driver being exploited is called “rwdrv.sys,” typically used for tuning software with Intel CPUs. Unfortunately, hackers misuse it to install “hlpdrv.sys,” allowing them to circumvent Defender and carry out unauthorized activities.
GuidePoint observed this specific method of attack beginning in mid-July, and it appears that the vulnerability has not yet been addressed. However, raising awareness about this issue can reduce the likelihood of it being effective against users.
In the meantime, our partners at Hotnchill suggest exploring reliable third-party antivirus options for your Windows PC. Staying informed about the latest developments, including potential defenses against Akira ransomware, is always beneficial.
