This talk examines a real-world incident in which an attacker exploited a vulnerability in a legitimate driver to enumerate installed antivirus products, fully evade their detection, and ultimately deploy MedusaLocker ransomware. Step by step, the report breaks down the technique, explains why it was effective, and shows practical ways to mitigate similar attacks.
Event: EkoParty
VIDEO RECORDING

- Red plus Blue makes Purple!/
- Public talks/
- 2025/
- CVE-2025-7771: Antivirus Evasion Through Legitimate Driver Abuse/
CVE-2025-7771: Antivirus Evasion Through Legitimate Driver Abuse
·1 min·


