Connect with us

CyberSecurity

Signed Microsoft Driver Weaponized: ‘GodDamn’ Ransomware Unleashes BYOVD Attacks on US Firms

Published

on

GodDamn ransomware BYOVD

A Signed Driver Turns Into a Weapon

A new ransomware strain dubbed GodDamn is making headlines for a particularly nasty trick: it leverages a Microsoft-signed kernel driver to disable endpoint security software before deploying its payload. The technique, known as Bring Your Own Vulnerable Driver (BYOVD), isn’t new—but the use of a legitimately signed driver makes it far harder to detect.

Security researchers at Trend Micro first spotted the campaign in late February 2025. The attackers are zeroing in on US-based organizations, including manufacturing firms, healthcare providers, and logistics companies. The goal? Disable defenses, steal data, and demand ransoms in cryptocurrency.

How BYOVD Turns a Signed Driver Into a Liability

BYOVD attacks work by exploiting a legitimate, signed kernel driver that contains a known vulnerability. In this case, the attackers use a driver signed by Microsoft that has a flaw allowing arbitrary code execution in kernel mode. Once loaded, the driver grants the ransomware the highest level of system access—ring 0—which lets it kill antivirus processes, delete backup files, and disable monitoring tools without triggering alerts.

The signed driver bypasses many security checks because the operating system trusts it. The attackers don’t need to exploit a zero-day; they just repurpose a driver that Microsoft already approved. This is the core of the BYOVD threat: the very mechanism meant to ensure trust becomes the attack vector.

Why US Companies Are in the Crosshairs

Trend Micro’s telemetry shows that GodDamn ransomware has hit at least 12 US organizations in the past month. The attackers appear to prioritize firms with weak endpoint detection and response (EDR) deployments—often smaller manufacturers or mid-sized healthcare groups that can’t afford layered security. Ransom demands range from $50,000 to $500,000, with payments directed to Bitcoin wallets.

The ransomware doesn’t just encrypt files; it exfiltrates data first. If the victim doesn’t pay, the attackers threaten to leak sensitive information on dark web forums. This double-extortion tactic has become standard in the ransomware ecosystem, but the BYOVD component gives GodDamn an edge: it can disable even the most aggressive EDR tools before they react.

The Technical Breakdown: What Happens Inside

When GodDamn infects a system, it drops a legitimate signed driver (often a known utility like aswArPot.sys or a similar driver from a security vendor) along with a loader. The loader calls the Windows service control manager to load the driver, which then communicates with the kernel. From there, the ransomware enumerates running processes and terminates anything related to security software—including antivirus engines, firewalls, and backup agents.

After clearing the defenses, GodDamn downloads its encryption module from a remote server. It uses a hybrid encryption scheme: AES-256 for file encryption and RSA-2048 for key protection. The ransomware targets over 400 file extensions, including databases, documents, and virtual machine images. It also deletes Volume Shadow Copies to prevent recovery without the decryption key.

Microsoft’s Response: A Patch and a Warning

Microsoft has since revoked the certificate used to sign the vulnerable driver and pushed a Windows Defender update that blocks the specific driver hash. The company also updated its Driver Blocklist policy to prevent the driver from loading on fully patched systems. However, the broader issue remains: any signed driver with a known vulnerability can be weaponized.

Security experts at Mandiant have urged organizations to implement driver blocklist policies proactively. They recommend using tools like Microsoft’s Driver Blocklist Policy or third-party solutions that monitor for unauthorized kernel driver loads. The key is to treat kernel-level access as a critical threat surface—even if the driver comes with a Microsoft stamp of approval.

Defending Against BYOVD Ransomware

Protecting against attacks like GodDamn requires a multi-layered approach. Here are the most effective steps security teams can take right now:

  • Enable driver blocklisting: Use Microsoft’s recommended blocklist or a third-party tool to prevent known vulnerable drivers from loading. Update the list regularly as new vulnerabilities are disclosed.
  • Deploy EDR with behavioral detection: Traditional signature-based antivirus won’t catch BYOVD. Endpoint detection and response tools that monitor for abnormal kernel driver loading can flag the attack early.
  • Restrict driver installation: Configure Windows Group Policy to only allow signed drivers from approved publishers. This won’t stop the attack entirely, but it adds friction.
  • Implement the principle of least privilege: Limit administrative rights on endpoints. BYOVD attacks often require admin-level access to load the driver, so reducing the number of privileged users reduces the attack surface.
  • Use application control: Tools like Windows Defender Application Control (WDAC) can block unauthorized executables, including driver loaders, from running.

The Bigger Picture: Trust but Verify

The GodDamn ransomware campaign is a stark reminder that digital signatures are not a guarantee of safety. Attackers are increasingly weaponizing signed drivers, and the security community is playing catch-up. Microsoft has improved its driver submission process in recent years, but the sheer volume of signed drivers makes it impossible to vet every one for latent vulnerabilities.

For now, the best defense is a healthy dose of skepticism. Treat every kernel driver—signed or not—as a potential threat. Monitor for unusual driver loading, keep blocklists updated, and assume that a signed driver can be turned against you. The attackers certainly are.

Continue Reading

CyberSecurity

Nightmare Eclipse Drops HardBreacher Exploit for Kaspersky Endpoint Security

Published

on

Kaspersky exploit HardBreacher

Another Zero-Day, Another Headache for Security Teams

The researcher known as Nightmare Eclipse has done it again. Over the weekend, the prolific bug hunter released a new proof-of-concept exploit dubbed HardBreacher, this time aimed at a privilege escalation flaw in Kaspersky Endpoint Security.

It’s the latest in a string of public disclosures from the researcher, who has been on a tear lately, dropping PoC exploits for a range of Windows and Microsoft Defender vulnerabilities. But this one hits a different target — and it sounds nasty.

Nightmare Eclipse, also known as Chaotic Eclipse, has been vocal about their frustration with how Microsoft handles vulnerability reports. That frustration has translated into a steady stream of public exploits. Most have stayed at the PoC stage, but a few have been picked up and weaponized by real-world attackers.

What HardBreacher Does

According to the researcher, HardBreacher exploits a privilege escalation vulnerability in Kaspersky Endpoint Security. The impact, if the exploit lands, is described in dramatic terms.

“The PoC is not in the best shape at all, it is basically duct taped, I just managed to make it work and that’s all,” Nightmare Eclipse wrote. Fair enough — but the effect is anything but amateur.

“The interesting part about this is Kaspersky completely loses it when you take control over the UI process,” the researcher added. “You can cause it to stop functioning, grant/block access to files it’s not supposed to. If the PoC succeeds, the entire operating system becomes a hot mess.”

That description suggests a full compromise of the endpoint protection agent, which is exactly what you’d expect from a privilege escalation flaw in a security product. When the thing that’s supposed to protect you turns into a weapon, the whole system is in trouble.

Kaspersky Says It’s Already Patched

SecurityWeek reached out to Kaspersky, and the company confirmed the underlying issue has been resolved.

“The corresponding fix is delivered via an automatic update, or users can trigger a database update manually,” a Kaspersky spokesperson said.

That’s good news for enterprises running Kaspersky Endpoint Security — assuming they’ve let the updates flow. The company’s response suggests the fix was already in the wild before the exploit went public, which is the best-case scenario for defenders.

A Pattern of Public Disclosures

HardBreacher isn’t the only recent release from Nightmare Eclipse. The researcher has also published ShieldBreak, which reportedly allows an attacker to spawn a shell with System privileges, and LegacyHive, another privilege escalation tool.

The trio of exploits paints a picture of a researcher who’s done with responsible disclosure and is now going public with findings. It’s a controversial approach, but one that’s increasingly common in the security world.

For defenders, the takeaway is straightforward: keep your endpoint security products updated, and take these public PoCs seriously. They’re not just theoretical exercises.

Related reading: Log4j remote code execution scare and critical Ruby on Rails vulnerability in attackers’ crosshairs show how quickly public disclosures turn into active exploitation.

What This Means for Your Organization

If you’re running Kaspersky Endpoint Security, the fix is already available. But the incident raises a broader question: how many other security products have similar flaws sitting undiscovered?

Security researchers are increasingly choosing public disclosure over coordinated vulnerability disclosure, and that trend isn’t going away. The best defense is a patch management process that doesn’t wait for the headlines.

Also worth remembering: Nightmare Eclipse’s earlier exploits have been exploited in the wild. The line between PoC and weapon is thin, and it only takes one attacker with a bit of ingenuity to cross it.

Stay updated, stay patched, and keep an eye on what this researcher does next.

Continue Reading

CyberSecurity

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Published

on

Android 17 ECH

Android 17 Brings ECH to the OS Level

Google has quietly rolled out a significant privacy upgrade in Android 17. The new version introduces support for Encrypted Client Hello (ECH), a standard that stops network providers from seeing which websites you visit. This isn’t just a browser tweak — it’s baked into the operating system itself.

For years, your internet service provider (ISP) could see the domain names of every site you accessed, even if the content was encrypted. ECH changes that by encrypting the part of the TLS handshake that reveals the server name. Now, with Android 17, that protection applies across the entire OS, not just in Chrome or Firefox.

The announcement came on Thursday, with Google positioning ECH as a cornerstone of its broader network security push. The company also highlighted efforts to shore up cellular vulnerabilities and protect home network privacy.

How ECH Works: The Technical Side

When you connect to a website, your device sends a TLS handshake that includes the domain name in plaintext. That’s how network providers know you’re visiting example.com even if the page itself is encrypted. ECH encrypts this handshake, so the server name is hidden from anyone sniffing the connection.

This is a big deal. DNS over HTTPS (DoH) and DNS over TLS (DoT) already hid your DNS queries, but the TLS handshake itself remained a leak. ECH closes that gap.

Android 17 implements ECH at the OS level, which means every app that uses the system’s network stack benefits automatically. You don’t need to configure anything or install a special browser. It just works.

What This Means for Your Privacy

For the average user, the practical effect is simple: your network provider can no longer build a profile of your browsing habits based on domain names. That’s a major win for privacy, especially on public Wi-Fi networks where snooping is easier.

It also matters for people in countries with strict internet censorship. ECH makes it harder for authorities to block access to specific sites, though it’s not a silver bullet — they can still block by IP address or use other techniques.

Beyond ECH: Other Security Upgrades in Android 17

ECH isn’t the only security feature in Android 17. Google also addressed cellular vulnerabilities that could expose your location or allow attackers to intercept calls. These fixes target the baseband processor, which handles radio communication and has historically been a weak point.

Home network privacy also got a boost. Android 17 now handles certain network configurations more securely, reducing the risk of man-in-the-middle attacks on your local network.

Here’s a quick rundown of what’s new:

  • OS-wide ECH support for encrypted TLS handshakes
  • Patches for cellular baseband vulnerabilities
  • Improved home network privacy protections
  • Seamless integration with existing apps — no developer action required

Why This Matters for Your Network Provider

Network providers have long relied on seeing domain names to throttle traffic, target ads, or comply with government requests. ECH undermines that visibility. Providers can still see your IP address and the amount of data you transfer, but they lose the ability to know exactly which sites you’re visiting.

That’s a significant shift. It’s also a reason why some ISPs have pushed back against ECH in the past, arguing it complicates network management and parental controls. Google’s decision to bake it into Android 17 suggests the company is prioritizing user privacy over carrier convenience.

If you’re concerned about your own setup, you might also want to explore how to change your DNS settings on Android for an extra layer of privacy, or check out the best VPN apps for Android to complement ECH.

How to Get Android 17 and ECH

Android 17 is rolling out now, but availability depends on your device. Pixel phones get it first, followed by other manufacturers. If you’re not sure whether your device has received the update, go to Settings > System > System update and check.

Once you’re on Android 17, ECH is enabled by default. There’s no toggle to flip or setting to hunt down. That’s the beauty of OS-level integration — it’s just there, protecting you without any effort.

For developers, the good news is you don’t need to change your apps. The system handles ECH transparently. If you’re building a network-heavy app, though, it’s worth testing to ensure everything still works as expected.

The Bottom Line

Android 17’s ECH support is a quiet but meaningful step forward for online privacy. It closes a long-standing gap in encrypted communications and does so in a way that requires zero user action. That’s rare in the security world, where the best protections often demand the most setup.

It’s not perfect — IP address leaks and other metadata remain — but it’s a solid improvement. If you value your privacy, updating to Android 17 is a no-brainer.

Continue Reading

CyberSecurity

TerminalFix: Fake Cloudflare CAPTCHAs Now Deliver Reverse-Tunnel Backdoors

Published

on

TerminalFix fake Cloudflare CAPTCHA

How TerminalFix Works

Microsoft has sounded the alarm on a new ClickFix variant, dubbed TerminalFix, that swaps the familiar Run dialog trick for something far more dangerous: a fake Cloudflare CAPTCHA that pushes victims into Windows Terminal or PowerShell.

Traditional ClickFix campaigns typically direct users to the Windows Run dialog (Win+R) and ask them to paste a command. TerminalFix takes a different route. It steers victims toward Windows Terminal or PowerShell instead, making it easier to slip in complex, multi-stage commands that would look suspicious in the old dialog box.

The result? A reverse-tunnel backdoor that gives attackers remote access to the compromised machine.

The Fake CAPTCHA Lure

Here’s how the attack unfolds. A user lands on a compromised or malicious website, often through a phishing email or a poisoned search result. A pop-up appears, mimicking a Cloudflare CAPTCHA challenge. The message asks the visitor to verify they’re human by running a command.

In reality, the “verification” is a malicious script. The command, when executed in PowerShell or Windows Terminal, downloads and runs a payload that establishes a reverse tunnel. That tunnel lets the attacker connect back to the system, bypassing firewalls and network restrictions.

The choice of Cloudflare branding is deliberate. CAPTCHAs are so routine that most users don’t think twice. They just want the page to load.

Why Windows Terminal Makes It Worse

ClickFix isn’t new — researchers have documented it for months. But the shift to Windows Terminal is a notable evolution. The Run dialog is a single line, easy to scan. Windows Terminal and PowerShell accept multi-line scripts, encoded payloads, and even obfuscated commands that are far harder to parse at a glance.

That complexity is exactly what attackers count on. A long, tangled string in PowerShell doesn’t raise red flags the way the same text might in the Run box. Users are more likely to paste and hit Enter, assuming it’s part of the CAPTCHA flow.

Microsoft’s threat intelligence team notes that TerminalFix increases the likelihood of success precisely because it exploits this gap in user awareness.

How to Protect Yourself

This attack relies on social engineering, not software vulnerabilities. That means the defense is mostly behavioral. Here’s what you should do:

  • Never paste commands from a webpage into a terminal. Legitimate CAPTCHAs never ask you to run code. If a site does, close it immediately.
  • Verify the URL. Fake CAPTCHA pages often appear on lookalike domains. Check the address bar before interacting with any pop-up.
  • Use a reputable ad blocker. Many of these attacks are delivered through malvertising and rogue ads. Blocking them reduces exposure.
  • Keep your system updated. Microsoft Defender and other security tools receive regular updates to detect new payloads like the ones used in TerminalFix.
  • Enable Attack Surface Reduction rules. If you’re an enterprise admin, configure ASR rules to block suspicious child processes from Office apps and browsers.

What to Do If You’re Already Compromised

If you suspect you’ve run one of these commands, act fast. Disconnect the machine from the network to cut off the reverse tunnel. Then run a full antivirus scan and look for unusual outbound connections.

For IT teams, Microsoft recommends reviewing Windows event logs for PowerShell execution and checking for newly created scheduled tasks or services. The reverse tunnel often uses tools like ngrok or similar services, so network logs may show connections to known tunneling domains.

Finally, change any credentials that might have been exposed. A backdoor of this kind can give attackers access to more than just the one machine — it can be a foothold into a broader network.

Bottom Line

TerminalFix is another reminder that the weakest link in security is often the person at the keyboard. The fake Cloudflare CAPTCHA is a clever disguise, but the underlying principle is old: trick someone into running something they shouldn’t.

Stay skeptical. If a website asks you to open a terminal to verify you’re human, it’s almost certainly a trap. And if you’re managing a fleet of Windows machines, make sure your users know the difference between a real CAPTCHA and a social engineering attempt.

For more on how to spot and block similar threats, check out our guide on phishing attack prevention and the latest on Windows security best practices.

Continue Reading

Trending