Researchers reported a Silver Fox campaign using fake software installers, including a sample named NVIDIA.exe, to deploy a vulnerable or malicious signed kernel driver and shut down endpoint protection on Windows systems. The installer drops a 25,056-byte driver as a randomly named file in a temporary directory, registers it as a kernel service, enables SeLoadDriverPrivilege, and loads it through NtLoadDriver. Once active, the driver exposes the \\.\NSecKrnl device and accepts IOCTL 0x2248E0 requests to terminate processes from a hardcoded list of security tools, with Chinese products such as 360 Antivirus specifically targeted.
The driver, NSecKrnl64, was reportedly signed by Shandong Anzai Information Technology CO., Ltd. and implements process termination through Windows kernel routines including PsLookupProcessByProcessId, ObOpenObjectByPointer, and ZwTerminateProcess. The activity aligns with bring your own vulnerable driver (BYOVD) tradecraft, where signed drivers are abused to bypass or disable defenses. Microsoft’s recommended driver block rules provide a relevant mitigation path, while defenders were urged to monitor driver and service installation from user-writable temp paths, registry changes under HKLM\SYSTEM\CurrentControlSet\Services, and subsequent kernel driver loads tied to suspicious installers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers identified a new Silver Fox campaign distributing fake application installers such as WinRAR and Telegram. The campaign used a sample named NVIDIA.exe to deploy a kernel driver and disable endpoint security products, with targeting that strongly suggests Chinese victims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.