Abusing Vulnerable Drivers to Disable System Defenses: The Case of ThrottleStop

  • Cristian H. M. Souza Kaspersky / USP
  • Eduardo O. Chavarro Kaspersky
  • Daniel M. Batista USP

Resumo


ThrottleStop.sys is a legitimate driver that has been abused by adversaries in recent years as part of Bring Your Own Vulnerable Driver (BYOVD) attacks to elevate privileges on Windows systems and weaken their defenses by terminating processes associated with Endpoint Detection and Response (EDR) tools. In this paper, we provide a detailed technical analysis of CVE-2025-7771, a vulnerability affecting this driver that was discovered by Kaspersky’s Global Emergency Response Team (GERT). We also present an indepth analysis of an advanced artifact that abuses this vulnerability in real-world attacks. Finally, we review the adversary’s tactics, techniques, and procedures (TTPs) and propose best practices for mitigating this type of threat.

Referências

Al-Karaki, J. N. (2025). Defense in depth: a multilayered approach. Defense in Depth: Modern Cybersecurity Strategies and Evolving Threats, pages 51–72.

Gupta, R., Dresel, L. P., Spahn, N., Vigna, G., Kruegel, C., and Kim, T. (2022). Popkorn: Popping windows kernel drivers at scale. In Proceedings of the 38th Annual Computer Security Applications Conference, pages 854–868.

Mohammed, A. (2023). Soc audits in action: Best practices for strengthening threat detection and ensuring compliance. Baltic Journal of Engineering and Technology, 2(1):62–69.

Monzani, A., Parata, A., Oliveri, A., Aonzo, S., Balzarotti, D., Lanzi, A., et al. (2026). Unveiling byovd threats: Malware’s use and abuse of kernel drivers. In Network and Distributed System Security (NDSS) Symposium 2026, pages 1–19. NDSS.

Poslušnỳ, M. (2022). Signed kernel drivers–unguarded gateway to windows’ core.

Soliven, R. and Kimura, H. (2022). Ransomware actor abuses genshin impact anti-cheat driver to kill antivirus. Trend Micro. URl: [link] (visited on Oct. 1, 2022).

Souza, C., Muñoz, A., Ovalle, E., Figurelli, F., and Leite, A. (2025a). Driver of destruction: How a legitimate driver is being used to take down av processes. Technical report, Kaspersky Securelist.

Souza, C. H., Pascoal, T., Neto, E. P., Sousa, G. B., SL Filho, F., Batista, D. M., and Silva, F. S. D. (2025b). Sdn-based solutions for malware analysis and detection: State-of-the-art, open issues and research challenges. Journal of Information Security and Applications, 93:104145.

Souza, C. H. M. and Batista, D. M. (2025). On the use of machine learning for modern iot elf malware detection. In 2025 IEEE Latin American Conference on Computational Intelligence (LA-CCI), pages 1–6.
Publicado
01/09/2026
SOUZA, Cristian H. M.; CHAVARRO, Eduardo O.; BATISTA, Daniel M.. Abusing Vulnerable Drivers to Disable System Defenses: The Case of ThrottleStop. In: TRILHA DE INTERAÇÃO COM A INDÚSTRIA E DE INOVAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 880-886. DOI: https://doi.org/10.5753/sbseg_estendido.2026.27078.