Skip to main content
  1. Home
  2. Computing
  3. News

Hackers have found a way to hack you that you’d never expect

Add as a preferred source on Google

A security flaw has allowed a ransomware gang to effectively prevent antivirus programs from running properly on a system.

As reported by Bleeping Computer, the BlackByte ransomware group is utilizing a newly discovered method related to the RTCore64.sys driver to circumvent more than 1,000 legitimate drivers.

A depiction of a hacker breaking into a system via the use of code.
Getty Images

Security programs that rely on such drivers are therefore unable to detect a breach, with the technique itself being labeled as “Bring Your Own Driver” by researchers.

Recommended Videos

Once the drivers have been turned off by the hackers, they can operate under the radar due to the lack of multiple endpoint detection and response (EDR). The vulnerable drivers are able to pass an inspection via a valid certificate, and they also feature high privileges on the PC itself.

Researchers from cybersecurity company Sophos detail how the MSI graphics driver that is targeted by the ransomware gang offers I/O control codes that can be accessed through user-mode processes. However, this element breaches Microsoft’s security guidelines on kernel memory access.

Due to the exploit, threat actors can freely read, write, or execute code within a system’s kernel memory.

BlackByte is naturally keen to avoid being detected so as to not have its hacks analyzed by researchers, Sophos stated — the company pointed toward attackers looking for any debuggers running on the system and then quitting.

Furthermore, the group’s malware scans the system for any potential hooking DLLs connected to Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security. Should any be found by the search, BlackByte disables its ability to function.

Because of the sophisticated nature of the technique used by the threat actors, Sophos warned that they will continue to exploit legitimate drivers in order to bypass security products. Previously, the “Bring Your Own Driver” method was seen being used by the North Korean hacking group Lazarus, which involved a Dell hardware driver.

Bleeping Computer highlights how system administrators can protect their PCs by putting the MSI driver (RTCore64.sys) that is being targeted into an active blocklist.

BlackByte’s ransomware efforts first came to light in 2021, with the FBI stressing that the hacking group was behind certain cyberattacks on the government.

Zak Islam
Former Contributor
Zak covers the latest news in the technology world, particularly the computing field. A fan of anything pertaining to tech…
How to change the default apps on a Mac
Apple's default apps are great, until they're not. Here's how to swap them out in seconds.
change default apps on Mac featured image

One of my favorite things about macOS is that it comes with default apps to handle your everyday tasks. You get Safari to browse the web, the Mail app to handle your emails, and the Preview app to open and view photos and PDFs.

But what if you want to use a third-party app you prefer over the default app? Thankfully, Apple makes it easy to change the default apps on your Mac. So, whether you want to use Google Chrome or Outlook, here’s how you can set them as the default on your Mac. 

Read more
You can now choose how hard Claude thinks before answering your queries
For the first time, Claude users can decide whether their AI assistant thinks fast or thinks deep.
Page, Text, Business Card

Anthropic just released Claude Opus 4.8, and while the benchmark improvements are quite real, the most meaningful change for everyday users is something far simpler. 

You can now tell Claude how hard to think before it responds to your query. Along with that, dynamic workflows are now available in research preview for Enterprise, Team, and Max plan users. 

Read more
Copilot gets a redesign and it now wants to do more without being an eyesore
Microslop Microsoft AI Copilot logo

Microsoft is giving Copilot a quiet but meaningful redesign, and this time the focus is not just on making it more powerful. It is about making it feel like something that naturally belongs in your workflow.

Across Microsoft 365, Copilot is being reshaped to reduce visual noise and increase usefulness. Instead of constantly demanding attention, it is being designed to sit in the background when needed and step forward only when it actually helps. That shift might sound subtle, but in day-to-day work, it changes how often you feel interrupted versus supported.

Read more