New Malware utilizes trusted Windows drivers to get around on security systems – here is how to remain safe


  • Chinese threat group abused a vulnerable watchdog -Antimalware -Driver to disable antivirus and EDR tools
  • Attackers also utilized a Zemana Anti-Malware Driver (Zam.exe) for wider compatibility across Windows
  • Researchers encourage IT -Teams to update Blocklists, use Yara rules and monitor for suspicious activity

Chinese Hackers Silver Fox has been seen abuse by a previously trusted Windows driver to disable antivirus protection and implement malware on target units.

The latest driver who is abused in the ancient “Bring Your Own Woundable Driver” attack is called watchdog antimalware, usually part of the security solution with the same name.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top