July 10, 2026
- Valkyrie-bot is deploying a WHQL-signed Windows kernel rootkit that operates as a device filter driver (
WindowsService.sys, signed under a Beijing-registered entity) rather than hooking syscalls, giving it a covert ring0↔ring3 memory-access channel that survives even after AV removes the userland dropper. Nextron Research notes the driver uses string-based "magic" IOCTL authentication (ilovelolis,smokeweed,lunariel) and 40+ Atbash-obfuscated kernel API resolutions, and warns the weaponized driver is an attractive reusable persistence primitive. Detection hooks include device-object enumeration (\\.\MEMCHK64) and IOCTL monitoring; a deobfuscation PoC was published. Nextron Research (X) · Malware & Endpoint Evasion
in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0