• Hausa Edition
  • Podcast
  • Conferences
  • LeVogue Magazine
  • Business News
  • Print Advert Rates
  • Online Advert Rates
  • Contact Us
Tuesday, July 1, 2025
Leadership Newspapers
Read in Hausa
  • Home
  • News
  • Politics
  • Business
  • Sport
  • Health
  • Entertainment
  • Opinion
    • Editorial
  • Columns
  • Football
  • Others
    • LeVogue Magazine
    • Conferences
    • National Economy
  • Contact Us
No Result
View All Result
  • Home
  • News
  • Politics
  • Business
  • Sport
  • Health
  • Entertainment
  • Opinion
    • Editorial
  • Columns
  • Football
  • Others
    • LeVogue Magazine
    • Conferences
    • National Economy
  • Contact Us
No Result
View All Result
Leadership Newspapers
No Result
View All Result

Blackbyte Ransomware Abuses Legit Driver to Disable Security Products, Says NCC – CSIRT

by Chima Akwaja
3 years ago
in NCC Watch
Blackbyte Ransomware
Share on WhatsAppShare on FacebookShare on XTelegram

The Nigerian Communications Commission‘s Computer Security Incident Response Team (NCC-CSIRT) has flagged a high-impact threat to Windows operating system, the Blackbyte Ransomware, which has the capacity to bypass protections by disabling more than 1,000 drivers used by various security solutions.

Advertisement

The NCC-CSIRT said the BlackByte ransomware gang, which is using a new technique that researchers called, „Bring Your Own Vulnerable Driver,“ is exploiting the security issue that allowed it to disable drivers that prevent multiple Endpoint Detection and Response (EDR) and antivirus products like Avast, Sandboxie, Windows DbgHelp Library, and Comodo Internet Security, from operating normally.

Recent attacks attributed to this group involved a version of the MSI Afterburner RTCore64.sys driver, which is vulnerable to a privilege escalation and code execution flaw tracked as CVE-2019-16098.

The “Bring Your Own Vulnerable Driver” (BYOVD) method is effective because the vulnerable drivers are signed with a valid certificate and run with high privileges on the system.

Two notable recent examples of BYOVD attacks include Lazarus, abusing a buggy Dell driver and unknown hackers abusing an anti-cheat driver/module for the Genshin Impact game.

RELATED

How NCC Is Tackling Financial Crimes In Nigeria

As FG Moves To Avert N27bn Loss From Damaged Fibre Cables

10 months ago
How NCC Is Tackling Financial Crimes In Nigeria

Highlighting The Role Of States In Internet Connectivity

11 months ago

The NCC-CSIRT advisory recommended that system administrators protect against BlackByte’s new security bypassing trick by adding the particular MSI driver to an active blocklist, monitoring all driver installation events, and scrutinising them frequently to find any rogue injections that do not have a hardware match.

The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

The CSIRT also works collaboratively with the Nigeria Computer Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.


We’ve got the edge. Get real-time reports, breaking scoops, and exclusive angles delivered straight to your phone. Don’t settle for stale news. Join LEADERSHIP NEWS on WhatsApp for 24/7 updates →

Join Our WhatsApp Channel

BREAKING NEWS: Nigerians can now earn US Dollars from the comfort of their homes with Ultra-Premium domains, acquire them for as low as $1700 and profit as much as $25,000. Click here to learn how you can earn US Dollars consistently.


Tags: Blackbyte Ransomware
SendShareTweetShare
Previous Post

Nigeria Needs Global Investments To Build Economy – Bagudu

Next Post

Pantami, Danbatta Shine As Nigeria Gets Re-elected As ITU Council Member

Chima Akwaja

Chima Akwaja

You May Like

How NCC Is Tackling Financial Crimes In Nigeria
NCC Watch

As FG Moves To Avert N27bn Loss From Damaged Fibre Cables

2024/08/28
How NCC Is Tackling Financial Crimes In Nigeria
NCC Watch

Highlighting The Role Of States In Internet Connectivity

2024/08/13
network
NCC Watch

Promoting Transparency In Data, Call Tariffs In Nigeria

2024/08/06
Senate Confirms Maida As NCC Executive Vice Chairman
NCC Watch

Assessing Nigeria’s Performance In Digital Transformation

2024/07/31
How NCC Is Tackling Financial Crimes In Nigeria
NCC Watch

Addressing Interconnect Indebtedness In ICT Sector

2024/07/23
How NCC Is Tackling Financial Crimes In Nigeria
NCC Watch

‘How FG Can Achieve 90,000km Fibre Project’

2024/07/17
Leadership Conference advertisement

LATEST

Nigeria And Brazil’s $1bn Deal: Can Mechanisation Boost Food Security?

Olukoyede’s Commissioning Of NDDC Projects In Perspective

Lafiagi: Protesters Free 4 Suspects, Destroy 6 Vehicles, Motorcycles At NDLEA Office — Police

Drug Abuse: Time To Confront The Issue

100th NEC Meeting: No Victor, No Vanquished, Says Saraki

Tinubu Seeks Visa Waiver Deal With OECS States

Tinubu Seeks Visa Waiver Deal With OECS Countries

Akpabio Calls For Increased Investment In Human Capital Devt

Senator Natasha Arraigned, Granted Bail

Protesters Torch NDLEA Office, Vandalise Monarch’s Palace In Kwara

© 2025 Leadership Media Group - All Rights Reserved.

No Result
View All Result
  • Home
  • News
  • Politics
  • Business
  • Sport
  • Health
  • Entertainment
  • Opinion
    • Editorial
  • Columns
  • Football
  • Others
    • LeVogue Magazine
    • Conferences
    • National Economy
  • Contact Us

© 2025 Leadership Media Group - All Rights Reserved.