Overall assessment:
This is a local privileged stealth driver, not a network-first implant.
Its feature set is built for process tampering, window hiding, synthetic input, controller-only access, and HWID-style spoofing.
Full report: https://t.co/JvuwjHpN4S
VirLabs analyzed a Windows kernel driver that behaves like a stealth/cheat-support/rootkit-style component: 0c45413122e68f4397fba9539fb74a67343a6496672c1a55862f95e2bcb105c3
No IOCTL cmd surface. Instead, a covert local control channel hidden behind registry-set notifications.
The spoofing layer targets hardware/user-visible identifiers.
The driver hooks or shims paths for disk, partition, mount manager, NVIDIA GPU, and nsiproxy/network-related queries, then randomizes or zeroes returned identifiers.
Classic HWID-spoofing behavior.
Réunion OSSIR du 07.07.26 à 14h
1️⃣ Gestion du risque fournisseur, par Mathieu Bernard et @EtienneRetout (GaLink)
2️⃣ Analyse de malwares par IA, par @JusticeRage (@VirLabs_AI)
3️⃣ Veille sécurité
Dans les locaux du Campus Cyber ou via Zoom
Inscription : https://t.co/13bY84SQZK