ClickFix to StealC: ResiLoader weaponizes pcdhost.sys BYOVD driver to achieve ring-0 code execution.
← Back to Labs
← Volver a Labs
Medium
Campaign, Malware
Defense Evasion
EDR, Sysmon, Windows

ClickFix to StealC: ResiLoader weaponizes pcdhost.sys BYOVD driver to achieve ring-0 code execution

ResiLoader drops the vulnerable pcdhost.sys driver in a BYOVD attack, using its kernel privileges to kill AV/EDR processes before hollowing ServiceModelReg.exe to execute StealC.

labs correlati

Contacts

Get in touch with us

Contact Us
chevron-right