New malware exploits Windows controllers to overcome security systems: here we show you how to stay safe


  • The group of Chinese threats abused a vulnerable surveillance antimalware controller to disable antivirus and EDR tools
  • The attackers also took advantage of a Zemana (Zam.exe) antimalware controller for wider compatibility in Windows
  • Researchers urge IT teams to update block lists, use yara rules and monitor suspicious activities

Chinese computer pirates Silver Fox have been seen abusing a previously reliable Windows controller to disable antivirus protections and implement malware on destination devices.

The last driver who abused the old attack of “bringing his own vulnerable controller” is called Watchdog antimalware, usually part of the security solution of the same name.

Leave a Comment

Your email address will not be published. Required fields are marked *