- Joined
- Sep 18, 2017
Original Story || Archive
Essentially, Gigabyte ignored an issue with its GDRV.SYS driver allowing hackers to exploit a vulnerability to gain kernel access. Having access they can install a dodgy kernel driver (RBNL.SYS) to then disable antivirus and other protections, then they can execute the RobbinHood ransomware to encrypt the victims files.
Verisign is also at fault as it hasn't revoked the signing certificate of the driver.
Essentially, Gigabyte ignored an issue with its GDRV.SYS driver allowing hackers to exploit a vulnerability to gain kernel access. Having access they can install a dodgy kernel driver (RBNL.SYS) to then disable antivirus and other protections, then they can execute the RobbinHood ransomware to encrypt the victims files.
Verisign is also at fault as it hasn't revoked the signing certificate of the driver.