Ransomware Attackers Abuse Genshin Impact Anti-Cheat System to Disable Antivirus

Share:

A vulnerable anti-cheat driver for the Genshin Impact video game has been leveraged by a cybercrime actor to disable antivirus programs to facilitate the deployment of ransomware, according to findings from Trend Micro.

The ransomware infection, which was triggered in the last week of July 2022, banked on the fact that the driver in question (“mhyprot2.sys”) is signed with a valid certificate, thereby making it possible to circumvent privileges and terminate services associated with endpoint protection applications.

Genshin Impact is a popular action role-playing game that was developed and published by Shanghai-based developer miHoYo in September 2020.

The driver used in the attack chain is said to have been built in August 2020, with the existence of the flaw in the module discussed after the release of the game, and leading to exploits demonstrating the ability to kill any arbitrary process and escalate to kernel mode.

The idea, in a nutshell, is to use the legitimate device driver module with valid code signing to escalate privileges from user mode to kernel mode, reaffirming how adversaries are constantly looking for different ways to stealthily deploy malware.

“The threat actor aimed to deploy ransomware within the victim’s device and then spread the infection,” incident response analysts Ryan Soliven and Hitomi Kimura said.

“Organizations and security teams should be careful because of several factors: the ease of obtaining the mhyprot2.sys module, the versatility of the driver in terms of bypassing privileges, and the existence of well-made proofs of concept (PoCs).”

In the incident analyzed by Trend Micro, a compromised endpoint belonging to an unnamed entity was used as a conduit to connect to the domain controller via remote desktop protocol (RDP) and transfer to it a Windows installer posing as AVG Internet Security, which dropped and executed, among other files, the vulnerable driver.

The goal, the researchers said, was to mass-deploy the ransomware to using the domain controller via a batch file that installs the driver, kills antivirus services, and launches the ransomware payload.

Trend Micro pointed out that the game “does not need to be installed on a victim’s device for this to work,” meaning threat actors can simply install the anti-cheat driver as a precursor to ransomware deployment.

We have reached out to miHoYo for comment, and we will update the story if we hear back.

“It is still rare to find a module with code signing as a device driver that can be abused,” the researchers said. “This module is very easy to obtain and will be available to everyone until it is erased from existence. It could remain for a long time as a useful utility for bypassing privileges.”

“Certificate revocation and antivirus detection might help to discourage the abuse, but there are no solutions at this time because it is a legitimate module.”

https://thehackernews.com/2022/09/ransomware-attackers-abuse-genshin.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:47 pm, Jul 8, 2025
weather icon 17°C
L: 15° | H: 19°
broken clouds
Humidity: 61 %
Pressure: 1020 mb
Wind: 3 mph W
Wind Gust: 3 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 71%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
15° | 19°°C 0.18 mm 18% 7 mph 61 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 17°°C 0 mm 0% 3 mph 61 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 16°°C 0 mm 0% 3 mph 58 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,901.94
0.78%
Ethereum(ETH)
€2,224.88
2.88%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.96
1.48%
Solana(SOL)
€128.90
2.05%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.145726
2.39%
Shiba Inu(SHIB)
€0.000010
2.68%
Pepe(PEPE)
€0.000009
3.63%
Scroll to Top