
← Back to Labs
← Volver a Labs
Medium
Campaign, Malware
Defense Evasion
EDR, Sysmon, Windows
ClickFix to StealC: ResiLoader weaponizes pcdhost.sys BYOVD driver to achieve ring-0 code execution
ResiLoader drops the vulnerable pcdhost.sys driver in a BYOVD attack, using its kernel privileges to kill AV/EDR processes before hollowing ServiceModelReg.exe to execute StealC.



