← BACK TO FEED
TAG

windows security4 articles

Microsoft's Own Defender Driver Can Be Turned Against Itself to Wipe Security Software

Check Point Research has revealed a technique called "BTR Reforged" that weaponizes Microsoft Defender's own legitimately signed boot-time driver, BTR.sys, to perform kernel-level file and registry operations — including deleting entire security software stacks — on all Windows versions from 7 through 11 25H2. Because BTR.sys is a built-in Windows component rather than a third-party driver, it cannot be blocklisted without breaking Defender itself, and a live demonstration at Black Hat USA 2026 showed it successfully removing Defender with Tamper Protection active. Microsoft has declined to issue a patch, stating the technique requires pre-existing administrative privileges and therefore does not meet its criteria for immediate servicing.

23 Aug 2026

Daxin Is Back, and It Brought a Friend: Meet Stupig, the Pre-Login Backdoor Nobody Saw Coming

A China-linked advanced malware called Daxin has resurfaced at a Taiwan manufacturing firm in 2026, over four years after it was first publicly documented, alongside a newly discovered backdoor called Stupig that hides within the Windows logon process to execute commands with SYSTEM privileges before any user signs in. Both tools carry 2013 compilation timestamps, raising the possibility the intrusion went undetected for up to 13 years. Separately, a suspected China-linked actor has also been observed using AI tools, including Anthropic's Claude Code and DeepSeek, to automate cyberattacks against government and financial targets across multiple countries.

27 Jul 2026

Meet Dolphin X: The Infostealer With an AI Profiler That Tells Crooks Which Victims Are Worth Robbing First

Varonis Threat Labs has discovered a new Windows malware called Dolphin X, sold on cybercrime forums, which targets over 300 applications and can steal credentials, cryptocurrency wallets, SSH keys, and cloud tokens. Its most notable feature is an AI Profiler that analyses victims' app usage, browsing history, and installed software to rank them by likely profitability, helping criminals prioritise their attacks — something researchers say has never been seen before in malware. Sold through a tiered subscription model starting at around $80 per month, the malware lowers the technical barrier for cybercriminals and includes advanced detection-evasion capabilities, prompting security experts to advise defenders to focus on behavioural threat detection rather than file signatures.

23 Jul 2026

OkoBot Malware Serves Fake Recovery Pages Inside Real Ledger and Trezor Apps

OkoBot is a Windows malware framework active since April 2025 that targets hardware wallet users through a module called SeedHunter, which injects fake recovery phrase prompts directly into legitimate Ledger and Trezor desktop applications rather than replacing them. The malware is delivered via ClickFix lures or trojanized software on GitHub, establishing persistent access through reverse SSH tunnels, patched RDP components, and a scheduled task called "Apple Sync," before deploying over 20 surveillance and theft modules. Kaspersky's research identified hundreds of victims across 25+ countries, but attribution remains unclear beyond soft indicators suggesting Russian-speaking threat actors.

17 Jul 2026