OldGremlin with old tricks
More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
OldGremlin with old tricks
OldGremlin is known as a ransomware group 😭. To stop antiviruses (and any programs, for that matter) from running, it loads TinyKiller, which consists of three files:
🐾 patcher_pdfw.exe — a patcher for loading avkd.sys;
🐾 avkd.sys — a malicious driver;
🐾 PdFwKrnl.sys — a legitimate AMD Radeon Driver driver, vulnerable to read and write.
The patcher actually exploits the CVE-2023-20598 vulnerability in the AMD driver to load its unsigned driver 😉. To do this, it uses an old trick — bypassing Driver Signature Enforcement (DSE) by turning off an internal flag. In Windows 8 versions up to build 9600, this parameter was called nt!g_CiEnabled and was located in ntoskrnl.exe. In subsequent versions, signature verification was handled by the internal parameter CI!g_CiOptions from CI.dll.
The process of obtaining the address of this parameter is quite labor-intensive 😫 and is fully described in this article. Once it has obtained the address of the flag, the patcher uses the vulnerable driver.
If you look at the message handler, the ioctls vulnerable to read and write are 0x80002014, 0x80002020, 0x80002028, and 0x8000202C 😨. The attacker uses the first option and constructs a packet to send to the driver:
BytesReturned = 0;
v5 = Msg;
for ( i = 0xCi64; i; --i )
*v5++ = 0;
*(_QWORD *)&Msg[0x18] = address;
*(_DWORD *)&Msg[0x28] = size; // eq 4
*(_QWORD *)&Msg[0x10] = output;
return DeviceIoControl(hDevice, 0x80002014, Msg, 0x30u, Msg, 0x30u, &BytesReturned, 0i64);
Here, address is the previously found offset of the flag. Inside the driver, this message reaches the following handler, which performs a direct memmove of the value address into output:
mov r8d, [IRP+28h] ; MaxCount
mov rdx, [IRP+18h] ; Src
mov rcx, [IRP+10h] ; Dst
call memmove
Obviously 😆, to disable the signature verification flag and write 0=disabled at this address, you simply need to swap the values of Msg[0x18] and Msg[0x10]. After launching the malicious driver, the value of the signature verification flag is restored and the vulnerable driver is unloaded from the system.
The technique of bringing along a vulnerable driver (BYOVD) is increasingly being used by attackers for various purposes 😶. Most of them use already known vulnerable drivers, the presence of which can be detected using LOLDrivers or by configuring Microsoft’s recommended blocklists. In addition, it is worth paying attention to the launch of driver services 😌.
OldGremlin uses the following commands to load the vulnerable driver and its own:
sc create vprovdrv binpath= "<path>\PdFwKrnl.sys" type= "kernel
sc start vprovdrv
sc create avkdriver binpath= "<path>\avkd.sys" type= "kernel
sc start avkdriver
IoCs
avkd.sys
eac69feccd33f6b97f7b60c1ded22d2b7f689921b28e531e7c2a925c09ce0936
patcher_pdwf.exe
116fbf458c1062303c2630116f8cad23d394106a5ddcc6d687f0f33dbe17a492
d236bfc015e735a64ad3c2d447fa70926b898a4e9b9af11f94b83ce768bbd434
PdFwKrnl.sys
0cf84400c09582ee2911a5b1582332c992d1cd29fcf811cb1dc00fcd61757db0
6945077a6846af3e4e2f6a2f533702f57e993c5b156b6965a552d6a5d63b7402
#APT #ioc
@ptescalator
More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…







