profile-img
Sophos X-Ops

@SophosXOps

A task force composed of our SophosLabs, SecOps, and SophosAI teams working together towards one goal: protecting our customers.

calendar_today14-10-2008 00:15:12

16,8K Tweets

75,0K Followers

342 Following

Sophos X-Ops(@SophosXOps) 's Twitter Profile Photo

Last year, after stopping a attack, X-Ops discovered the attackers had managed to sabotage endpoint protection tools using a malicious driver signed by Microsoft. We reported the issue the Microsoft and continued to investigate.

account_circle
Sophos X-Ops(@SophosXOps) 's Twitter Profile Photo

But after we published detection signatures that could block the drivers, we were surprised to discover dozens more of the criminal tools had been created and signed -- months earlier than we suspected.

account_circle
Sophos X-Ops(@SophosXOps) 's Twitter Profile Photo

Today, after a monthslong collaboration with Microsoft, they've invalidated this much larger collection of malicious drivers we reported to them as part of the Patch Tuesday release. In total, X-Ops discovered 133 malicious drivers, 100 of which were signed by Microsoft's WHCP.

account_circle