Researchers identified a malware campaign that utilized a Microsoft-verified Windows kernel driver to disable 145 antivirus and endpoint security applications This article explores identified malware. . The operators utilized hidden redirect GitHub pages and a Cloudflare-protected traffic layer to alter payload servers without updating the public lure pages.

After gaining elevated privileges, the malware deployed a kernel driver named Alinubx.sys, saved as nvfsflt64.sys and registered as the “NVIDIA File System Filter Driver.” The driver carried a Microsoft Windows Hardware Compatibility Publisher signature chain, helping the malicious component appear trusted to Windows and security controls, despite its ability to kill security software. It employed a kernel-level process termination method to shut down targeted products, including those shielded by Windows Protected Process Light technology.

The malware also collected cryptocurrency wallet files, Discord tokens, Steam session data, Telegram information, Windows Credential Manager data, screenshots, and documents containing terms like "password," "seed," "wallet," and "recovery." The collected information was compressed into a ZIP file and sent to the reported command-and-control endpoint at 2.26.126[.]50. According to a LastPass Threat Intelligence report, security teams should investigate systems showing the creation of the NvFsFilter service or writes to C:\Windows\System32\drivers\nvfsflt64.sys.

Organizations should also monitor for renamed vsdbg.exe processes launching unusual child processes, kernel driver loads followed by mass termination of security tools, and large ZIP downloads from suspicious GitHub Pages lures.