Ransomware-Angreifer missbrauchen Genshin Impact Anti-Cheat-System, um Antivirus zu deaktivieren

Teilen:

A vulnerable anti-cheat driver for the Genshin Impact video game has been leveraged by a cybercrime actor to disable antivirus programs to facilitate the deployment of ransomware, according to findings from Trend Micro.

The ransomware infection, which was triggered in the last week of July 2022, banked on the fact that the driver in question (“mhyprot2.sys”) is signed with a valid certificate, thereby making it possible to circumvent privileges and terminate services associated with endpoint protection applications.

Genshin Impact is a popular action role-playing game that was developed and published by Shanghai-based developer miHoYo in September 2020.

The driver used in the attack chain is said to have been built in August 2020, with the existence of the flaw in the module discussed after the release of the game, and leading to exploits demonstrating the ability to kill any arbitrary process and escalate to kernel mode.

The idea, in a nutshell, is to use the legitimate device driver module with valid code signing to escalate privileges from user mode to kernel mode, reaffirming how adversaries are constantly looking for different ways to stealthily deploy malware.

“The threat actor aimed to deploy ransomware within the victim’s device and then spread the infection,” incident response analysts Ryan Soliven and Hitomi Kimura sagte.

“Organizations and security teams should be careful because of several factors: the ease of obtaining the mhyprot2.sys module, the versatility of the driver in terms of bypassing privileges, and the existence of well-made proofs of concept (PoCs).”

In the incident analyzed by Trend Micro, a compromised endpoint belonging to an unnamed entity was used as a conduit to connect to the domain controller via remote desktop protocol (RDP) and transfer to it a Windows installer posing as AVG Internet Security, which dropped and executed, among other files, the vulnerable driver.

The goal, the researchers said, was to mass-deploy the ransomware to using the domain controller via a batch file that installs the driver, kills antivirus services, and launches the ransomware payload.

Trend Micro pointed out that the game “does not need to be installed on a victim’s device for this to work,” meaning threat actors can simply install the anti-cheat driver as a precursor to ransomware deployment.

We have reached out to miHoYo for comment, and we will update the story if we hear back.

“It is still rare to find a module with code signing as a device driver that can be abused,” the researchers said. “This module is very easy to obtain and will be available to everyone until it is erased from existence. It could remain for a long time as a useful utility for bypassing privileges.”

“Certificate revocation and antivirus detection might help to discourage the abuse, but there are no solutions at this time because it is a legitimate module.”

https://thehackernews.com/2022/09/ransomware-attackers-abuse-genshin.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:21 am, Juli 9, 2025
Wetter-Symbol 16°C
L: 14° | H: 18°
broken clouds
Luftfeuchtigkeit: 69 %
Druck: 1019 mb
Wind: 3 mph W
Windböe: 3 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 71%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:54 am
Sonnenuntergang: 9:16 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 18°°C 0.18 mm 18% 7 mph 69 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sa. Juli 12 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 3 mph 69 % 1020 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 3 mph 64 % 1020 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 5 mph 60 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,965.07
0.74%
Ethereum(ETH)
€2,230.33
2.90%
Fesseln(USDT)
€0.85
0.02%
XRP(XRP)
€1.97
1.50%
Solana(SOL)
€129.36
2.02%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.146045
2.34%
Shiba Inu(SHIB)
€0.000010
2.44%
Pepe(PEPE)
€0.000009
3.64%
Nach oben scrollen