ADVERTISEMENT
TechEconomy
Saturday, June 7, 2025
No Result
View All Result
Advertisement
ADVERTISEMENT
No Result
View All Result
ColorMag Dark
No Result
View All Result
Podcast

Home » Blackbyte Ransomware Abuses Legit Driver to Disable Security Products – NCC-CSIRT

Blackbyte Ransomware Abuses Legit Driver to Disable Security Products – NCC-CSIRT

Justice Godfrey Okamgba by Justice Godfrey Okamgba
October 8, 2022
in News
3

RelatedPosts

Mohammed Idris, minister of Information and National Orientation (Insert GOCOP' book cover) -

Minister of Information to Chair GOCOP Book Launch in Abuja

June 6, 2025

NITDA Boss Calls for Tech Policies Covering 35 million Nigerians with Special Needs

June 6, 2025
UBA
Advertisements

The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has flagged a high-impact threat to Windows operating system, the Blackbyte Ransomware, which has the capacity to bypass protections by disabling more than 1,000 drivers used by various security solutions.

The NCC-CSIRT said the BlackByte ransomware gang, which is using a new technique that researchers called, “Bring Your Own Vulnerable Driver,” is exploiting the security issue that allowed it to disable drivers that prevent multiple Endpoint Detection and Response (EDR) and antivirus products like Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security, from operating normally.

Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.

The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with high privileges on the system.

Two notable recent examples of BYOVD attacks include Lazarus, abusing a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the Genshin Impact game.

The NCC-CSIRT advisory recommended that system administrators protect against BlackByte’s new security bypassing trick by adding the particular MSI driver to an active blocklist, monitoring all driver installation events, and scrutinising them frequently to find any rogue injections that do not have a hardware match.

The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

The CSIRT also works collaboratively with the Nigeria Computer Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.

Loading

Advertisements
MTN ADS

Author

  • Justice Godfrey Okamgba
    Justice Godfrey Okamgba

    View all posts
0Shares
Previous Post

UPDATE: BNB Smart Chain Hack now Contained

Next Post

Bitget Sets to List Over 130 New Web3 Projects Next Month

Justice Godfrey Okamgba

Justice Godfrey Okamgba

Related Posts

Mohammed Idris, minister of Information and National Orientation (Insert GOCOP' book cover) -
News

Minister of Information to Chair GOCOP Book Launch in Abuja

by Staff Writer
June 6, 2025
0

Mohammed Idris, minister of Information and National Orientation, is to chair the public presentation of the book Nigeria Media Renaissance:...

Read more
35 million Nigerians and NITDA

NITDA Boss Calls for Tech Policies Covering 35 million Nigerians with Special Needs

June 6, 2025
TD Africa and Dell Technologies

TD Africa Deepens Strategic Ties with Dell Technologies in High-Level Executive Visit

June 6, 2025
NIMC NINAuth

NIMC Speaks over Police Commission’s Claim of Access Denial on Verification Platform

June 5, 2025
SIFAX Group

SIFAX Group Honoured with Distinguished Gender Inclusion Award  

June 2, 2025
Interswitch partners with PKB

Interswitch, PKB to Boost Lagos Smart Health Information Platform

May 31, 2025
Next Post

Bitget Sets to List Over 130 New Web3 Projects Next Month

Comments 3

  1. Pingback: Blackbyte Ransomware Abuses Legit Driver to Disable Security Products | #itsecurity | #infosec - NATIONAL CYBER SECURITY NEWS TODAY
  2. Pingback: Blackbyte Ransomware Abuses Legit Driver to Disable Safety Merchandise – NCC-CSIRT - Best News World
  3. Pingback: Blackbyte Ransomware Abuses Legit Driver to Disable Security Products - NCC-CSIRT – TechEconomy Nigeria - TechEconomy.ng - news mania

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

No Result
View All Result

Recent Posts

  • Healthcare: AMCE Opens its Doors to the Public
  • Identigo Launches in Lagos to Combat Fraud with Hybrid Verification Platform
  • How Agile Project Management and the Scrum Framework Are Powering the Next Generation of Software in Africa
  • Google Turning AI into Action: How Data is Saving Lives and Cities in Africa
  • Minister of Information to Chair GOCOP Book Launch in Abuja

Archives

  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • May 2019
  • April 2019
  • February 2019
  • September 2018
  • May 2018
  • March 2018
  • December 2017

Categories

  • Apply
  • Business
    • Commerce
    • Environment
    • Mobility
    • Security
    • StartUPs
    • TE Insights
    • Telecoms
    • Travel
  • BusinesSENSE For SMEs
  • Digital Lens
  • Economy
    • Digital Assets
    • Finance
    • Fintech
    • Insurance
    • Personal Finance
  • Entertainment
  • Fashion
  • Features
    • Appointment
    • Editorial
    • EventDIARY
    • Guest Writer
    • IndustryINFLUENCERS
    • Partners
  • Food & Health
  • Health
  • Macro Monday
  • MarkTECH
  • Media
    • Podcast
    • Videos
  • News
    • Politics
    • Sports
    • World
  • News2
    • EduTECH
    • NewsEXTRA
  • Postal
  • Startup
  • TBS
  • Tech
    • Broadband
    • ConsumerTech
      • Accessories
      • Apps
      • Gadgets and Appliances
      • Laptop
      • Phones
      • Reviews
      • Unboxing
    • DisruptiveTECH
    • How To
    • TechTAINMENT
  • TechCOMMUNITY
  • Technology
  • WomenPreneurs

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent

  • Healthcare: AMCE Opens its Doors to the Public
  • Identigo Launches in Lagos to Combat Fraud with Hybrid Verification Platform
  • How Agile Project Management and the Scrum Framework Are Powering the Next Generation of Software in Africa
  • Google Turning AI into Action: How Data is Saving Lives and Cities in Africa

Categories

  • Accessories
  • Apply
  • Appointment
  • Apps
  • Broadband
  • Business
  • BusinesSENSE For SMEs
  • Commerce
  • ConsumerTech
  • Digital Assets
  • Digital Lens
  • DisruptiveTECH
  • Economy
  • Editorial
  • EduTECH
  • Entertainment
  • Environment
  • EventDIARY
  • Fashion
  • Features
  • Finance
  • Fintech
  • Food & Health
  • Gadgets and Appliances
  • Guest Writer
  • Health
  • How To
  • IndustryINFLUENCERS
  • Insurance
  • Laptop
  • Macro Monday
  • MarkTECH
  • Media
  • Mobility
  • News
  • News2
  • NewsEXTRA
  • Partners
  • Personal Finance
  • Phones
  • Podcast
  • Politics
  • Postal
  • Reviews
  • Security
  • Sports
  • Startup
  • StartUPs
  • TBS
  • TE Insights
  • Tech
  • TechCOMMUNITY
  • Technology
  • TechTAINMENT
  • Telecoms
  • Travel
  • Unboxing
  • Videos
  • WomenPreneurs
  • World

Gallery

We love WordPress and we are here to provide you with professional looking WordPress themes so that you can take your website one step ahead. We focus on simplicity, elegant design and clean code.

Contains all features of free version and many new additional features.

  • A homepage section
  • About Us
  • Ads Page
  • Buy Adspace
  • Careers
  • Contact Us
  • Contact Us
  • Copyright
  • Entertainment
  • Fashion
  • Food & Health
  • Hide Ads for Premium Members
  • Home
  • Home 2
  • Home 4
  • Home 5
  • Home 6
  • Manage Subscriptions
  • News
  • Newsletter
  • Newsletter
  • Newsletter
  • Newsletter
  • Pin Posts
  • Podcast
  • Politics
  • Privacy Policy
  • Privacy Policy
  • Sample Page
  • Sports
  • TECHECONOMY
  • Techeconomy
  • TECHECONOMY TV
  • Techeconomy2
  • Technology
  • Terms & Conditions
  • ThemeGrill Demo Showcase
  • Travel
  • World

© 2025 Techeconomy - Designed by Opimedia.

No Result
View All Result
  • A homepage section
  • About Us
  • Ads Page
  • Buy Adspace
  • Careers
  • Contact Us
  • Contact Us
  • Copyright
  • Entertainment
  • Fashion
  • Food & Health
  • Hide Ads for Premium Members
  • Home
  • Home 2
  • Home 4
  • Home 5
  • Home 6
  • Manage Subscriptions
  • News
  • Newsletter
  • Newsletter
  • Newsletter
  • Newsletter
  • Pin Posts
  • Podcast
  • Politics
  • Privacy Policy
  • Privacy Policy
  • Sample Page
  • Sports
  • TECHECONOMY
  • Techeconomy
  • TECHECONOMY TV
  • Techeconomy2
  • Technology
  • Terms & Conditions
  • ThemeGrill Demo Showcase
  • Travel
  • World

© 2025 Techeconomy - Designed by Opimedia.

Translate »
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.