Hackers Use ThrottleStop: How Intel Driver Opens the Door for Akira Virus.
Cybersecurity experts have discovered a new way to bypass Microsoft Defender's protection, allowing attackers to install the ransomware virus Akira. This scheme exploits a vulnerability in the legitimate driver rwdrv.sys, which is part of the ThrottleStop tool for Intel processors.
By leveraging this vulnerability, attackers can gain access to the operating system's kernel to load their malicious driver hlpdrv.sys. This driver alters the Windows registry and disables Microsoft Defender's protective features, paving the way for attacks. According to experts, this is how the Akira virus has been spreading recently, with a surge in infections beginning in July.
Specialists emphasize that even legitimate programs can contain dangerous drivers that become tools for potential attacks.
Experts found that hackers managed to bypass Microsoft Defender's protection by exploiting a vulnerability in the ThrottleStop driver for Intel processors. This allowed them to install the Akira ransomware and gain access to the system, circumventing security. Specialists stress the importance of continuously ensuring the security of computer systems and avoiding the use of dangerous drivers.
Read also
- Antique Musket Balls Repurposed Into Solar Cells with 94% Efficiency
- South Korea Patents a Silent Engine for Air Taxis
- 144 FPS at 4K: A Gamer Pairs an RTX 3090 and RTX 3050 for Stunning Performance
- Snapdragon 8 Elite Gen 5: Qualcomm’s New Chip Targets Sub-$600 Smartphones
- Samsung Unveils Three New Odyssey Gaming Monitors: Specs and Features Revealed
- Plastic Waste Converted into Jet Fuel: New Breakthrough by Chinese Researchers

