HIDDENDRIVER is a Windows kernel rootkit derived from the open-source Hidden project. It was used in REF3927 activity, an opportunistic campaign attributed to a Chinese-speaking threat actor that compromised Windows IIS/ASP.NET servers and deployed multiple post-exploitation tools. HIDDENDRIVER uses Direct Kernel Object Manipulation to conceal processes, including unlinking process objects from system process-tracking structures. It also registers kernel object, process-creation, file-system minifilter, and registry callbacks to hide configured processes, files, directories, registry keys, and registry values, and can restrict access to protected processes. A Chinese-language user-mode controller, referred to as HIDDENCLI or HijackDriverManager, configures the driver and issues IOCTL commands to enable or disable functions and manage hidden objects and process rules. Its primary purpose is defense evasion by concealing malicious payloads and associated artifacts on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Internally, we are calling the rootkit HIDDENDRIVER and the userland application HIDDENCLI. This malicious software is a modified version of the open source rootkit Hidden.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker hid their presence on the infected machine by deploying a kernel rootkit... Internally, we are calling the rootkit HIDDENDRIVER and the userland application HIDDENCLI.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modified rootkit used to hide malicious payloads and artifacts on compromised machines.
A modified kernel-mode rootkit derived from the open-source 'Hidden' project. Uses DKOM and kernel callbacks/minifilters/registry callbacks to hide processes, files/directories, and registry artifacts; protects selected processes by downgrading handle access; and exposes an IOCTL interface for a userland controller to manage hiding/protection rules and enable/disable functionality.
Modified Windows kernel rootkit derived from the open-source Hidden project. It uses DKOM and kernel callbacks/filters to hide and protect processes, conceal files and directories, suppress registry keys and values, and hide its own artifacts. It is configured and controlled through IOCTL commands.
Windows trojan identified by unique byte patterns and strings associated with its execution and functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.