daily cyber × ai intelligence

index

tagged

[valkyrie-bot]

1 edition · 1 item

July 10, 2026

  • Valkyrie-bot is deploying a WHQL-signed Windows kernel rootkit that operates as a device filter driver (WindowsService.sys, signed under a Beijing-registered entity) rather than hooking syscalls, giving it a covert ring0↔ring3 memory-access channel that survives even after AV removes the userland dropper. Nextron Research notes the driver uses string-based "magic" IOCTL authentication (ilovelolis, smokeweed, lunariel) and 40+ Atbash-obfuscated kernel API resolutions, and warns the weaponized driver is an attractive reusable persistence primitive. Detection hooks include device-object enumeration (\\.\MEMCHK64) and IOCTL monitoring; a deobfuscation PoC was published. Nextron Research (X) · Malware & Endpoint Evasion

in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0