216.73.216.6

How ToddyCat tried to hide behind AV software

· Published 07/04/2025 12:54 · Modified 07/04/2025 15:04

Export JSON

Essential information

Published
07/04/2025 12:54
Modified
07/04/2025 15:04
Tags
2025-04-07 CVE-2021-36276 CVE-2024-11859 byovd dll proxying edrsandblast eset kernel manipulation tcesb
Related entities
1 intrusion sets (apt), 2 malware

Description

The ToddyCat APT group has developed a sophisticated tool called to stealthily execute payloads and evade detection. This tool exploits a vulnerability () in Command line scanner for , using a modified version of the open-source malware. employs techniques like , kernel memory manipulation, and Bring Your Own Vulnerable Driver () to bypass security solutions. It searches for kernel structure addresses using CSV or PDB files, installs a vulnerable Dell driver, and decrypts AES-128 encrypted payloads. The discovery highlights the need for monitoring driver installations and Windows kernel debug symbol loading events to detect such sophisticated attacks.

External references