• News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Commerce & Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
Friday, December 19, 2025
  • Login
No Result
View All Result
NEWSLETTER
Tech | Business | Economy
  • News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Commerce & Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
  • Chidiverse
  • News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Commerce & Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
  • Chidiverse
No Result
View All Result
Tech | Business | Economy
No Result
View All Result
  • News
  • Finance
  • StartUPs
  • TechTAINMENT
  • Guest Writer
  • Digital Assets
  • IndustryINFLUENCERS
  • Environment
  • Macro Monday
ADVERTISEMENT

Home » Blackbyte Ransomware Abuses Legit Driver to Disable Security Products – NCC-CSIRT

Blackbyte Ransomware Abuses Legit Driver to Disable Security Products – NCC-CSIRT

Justice Godfrey Okamgba by Justice Godfrey Okamgba
October 8, 2022
in News
Reading Time: 2 mins read
3

RelatedPosts

Avon Medical Unveils ₦200 Million Enhanced ICU Facility

UAE Tables $1bn to Finance AI Projects in Africa

Keepit Cloud Computing Predictions for 2026

UBA
Advertisements

The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has flagged a high-impact threat to Windows operating system, the Blackbyte Ransomware, which has the capacity to bypass protections by disabling more than 1,000 drivers used by various security solutions.

The NCC-CSIRT said the BlackByte ransomware gang, which is using a new technique that researchers called, “Bring Your Own Vulnerable Driver,” is exploiting the security issue that allowed it to disable drivers that prevent multiple Endpoint Detection and Response (EDR) and antivirus products like Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security, from operating normally.

Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.

The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with high privileges on the system.

MTN New

Two notable recent examples of BYOVD attacks include Lazarus, abusing a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the Genshin Impact game.

The NCC-CSIRT advisory recommended that system administrators protect against BlackByte’s new security bypassing trick by adding the particular MSI driver to an active blocklist, monitoring all driver installation events, and scrutinising them frequently to find any rogue injections that do not have a hardware match.

The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

The CSIRT also works collaboratively with the Nigeria Computer Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.

0Shares

stanbic
Justice Godfrey Okamgba

Justice Godfrey Okamgba

Related Posts

Avon Medical ICU

Avon Medical Unveils ₦200 Million Enhanced ICU Facility

by Destiny Eseaga
December 19, 2025
0
0

Avon Medical Practice has expanded its critical-care capacity with the launch of a fully enhanced Intensive Care Unit (ICU). The...

UAE Tables $1bn to Finance AI Projects in Africa

UAE Tables $1bn to Finance AI Projects in Africa

by Peter Oluka
December 18, 2025
0
0

The United Arab Emirates (UAE) has announced the launch of the 'AI for Development' initiative, worth US$1 billion, to support...

SAP Cloud | Keepit

Keepit Cloud Computing Predictions for 2026

by Peter Oluka
December 18, 2025
0
0

Last year, Keepit predicted that 2025 would be the year SaaS data protection stops being optional and becomes a must-have, as...

Vertiv and PurgeRite

Vertiv Completes $1.0 billion Acquisition of PurgeRite

by Destiny Eseaga
December 18, 2025
0
0

Vertiv Holdings Co., a global provider of critical digital infrastructure and continuity solutions, has announced the successful completion of its...

Professor Joash Amupitan, chairman of INEC

INEC: Amupitan Outlines Infrastructure, Voter Education Priorities

by Destiny Eseaga
December 18, 2025
0
0

When Professor Joash Amupitan walked into Room 107 of the Senate New Wing on Tuesday, December 16, 2025, it was...

Open governance and NITDA

Nigeria Reaffirms Commitment to Open Digital Governance

by Peter Oluka
December 18, 2025
0
0

Kashifu Inuwa, the director general of the National Information Technology Development Agency (NITDA), has reaffirmed Nigeria’s commitment to open governance,...

Load More
Next Post

Bitget Sets to List Over 130 New Web3 Projects Next Month

Comments 3

  1. Pingback: Blackbyte Ransomware Abuses Legit Driver to Disable Security Products | #itsecurity | #infosec - NATIONAL CYBER SECURITY NEWS TODAY
  2. Pingback: Blackbyte Ransomware Abuses Legit Driver to Disable Safety Merchandise – NCC-CSIRT - Best News World
  3. Pingback: Blackbyte Ransomware Abuses Legit Driver to Disable Security Products - NCC-CSIRT – TechEconomy Nigeria - TechEconomy.ng - news mania

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

MTN New
UBA
Advertisements
  • About Us
  • Advertise
  • Careers
  • Contact Us

© 2025 TECHECONOMY.

No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • Politics
  • Business
  • Science
  • Tech
  • Entertainment
  • Lifestyle

© 2025 TECHECONOMY.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.