Security1 distinct publisher3 min readUpdated
Check Point says Microsoft's signed BTR.sys remediation driver can be repurposed as a kernel operation engine with no vulnerable driver needed. Signature-based blocking does not apply.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Check Point says Microsoft's signed BTR.sys remediation driver can be repurposed as a kernel operation engine with no vulnerable driver needed. Signature-based blocking does not apply.
Follow any of these and your For You feed starts watching them — no settings page required.
Check Point has reverse engineered BTR.sys, Microsoft Defender's Boot-Time Removal driver, and demonstrated that the signed remediation component can be repurposed as a universal kernel operation engine to bypass endpoint security products, without any bring-your-own-vulnerable-driver step [1]. That takes away the two controls most teams lean on against kernel tampering, because as researcher Jiri Vinopal put it, "Because BTR.sys is a legitimate Microsoft-signed component, signature-based blocking is ineffective" [2].
The timing element matters as much as the signature. According to Check Point, the technique works by exploiting a "golden window" between system start and user mode initialization [1]. That is precisely the interval in which an EDR agent's user-mode components are not yet arbitrating anything, and it is the interval that most detection engineering treats as somebody else's problem. Vinopal also notes that a well-crafted weaponization tool, such as the BTR_CLI proof of concept, "intentionally mimics the operational footprint of the legitimate Windows Defender remediation process" [3]. Behavioural detection on a driver that is supposed to delete things at boot is a hard problem, and the research is explicit that the mimicry is deliberate.
The same bulletin from The Hacker News frames the week's pattern as trusted things doing what they were allowed to do: signed drivers turned against defences, legitimate applications helping malware blend in, and a weak header check opening a path to code execution [4]. Among the named items are a Gogs 10.0 remote code execution issue and an n8n workflow-to-RCE [5]. The summary text we were supplied does not give version-level detail or identifiers for either, so treat the vendor advisories as the source of record before you plan a maintenance window; the operational point stands regardless, which is that self-hosted Git and workflow-automation servers are unauthenticated-reachable code execution targets when they face the internet.
The blend-in half of the pattern has a live example. A new Grandoreiro campaign abuses the legitimate Duplicate Files Finder application to run malicious code by DLL sideloading, and Acronis telemetry puts the activity mostly in Latin America, with Mexico, Spain, Peru and Argentina accounting for most infections [6]. Acronis says the initial sample runs sandbox detection, virtual machine artefact checks, process blacklisting and environment profiling before it tries to reach command-and-control at all [7].
The week's other consequential item is enforcement rather than engineering. The Justice Department charged 17 members of the Mabna Institute, an Iran-based company that since at least 2013 intruded into 144 US universities, 178 foreign universities, at least 42 US and 11 foreign private sector companies, at least five US federal and state agencies, and at least two NGOs [8], which is at least 382 named institutions in total [9]. The DoJ says the campaign ran from approximately 2013 through at least December 2017 [10], that the defendants acted for the Islamic Revolutionary Guard Corps, and that stolen data was resold through Megapaper.ir and Gigapaper.ir [11]. More than 31 TB of academic data and intellectual property was taken, and of more than 100,000 professor accounts targeted, roughly 8,000 were compromised [12], a hit rate near 8 percent [13]. The State Department is offering a $10 million reward for information on five of the defendants or associated individuals and entities [14]. Check Point's Shmuel Gihon called Mabna "the privatization of state espionage: a contractor selling stolen research to whoever's paying, with the IRGC as an anchor client rather than a sole owner" [15].
What to watch: whether Microsoft treats BTR.sys as a component needing hardening or revocation rather than an accepted-risk signed binary, since blocklists do not help here [1][2]. Also watch for exploitation reports against exposed Gogs and n8n instances now that both are named in a widely read bulletin [5].
Ranked by verification strength, evidence, and original report placement.
Check Point reverse engineered Microsoft Defender's Defender Boot-Time Removal driver (BTR.sys) and demonstrated it is possible to repurpose the signed remediation driver as a universal kernel operation engine to bypass endpoint security solutions by exploiting a "golden window" between system start and user mode initialization, without relying on the bring your own vulnerable driver (BYOVD) method.
Security researcher Jiri Vinopal said: "Because BTR.sys is a legitimate Microsoft-signed component, signature-based blocking is ineffective."
Vinopal said a well-crafted weaponization tool (like BTR_CLI) intentionally mimics the operational footprint of the legitimate Windows Defender remediation process.
The Hacker News ThreatsDay bulletin frames the week as trouble starting with something trusted doing exactly what it was allowed to do: signed drivers get turned against defenses, legitimate apps help malware blend in, and a weak header check opens a path to code execution.
The bulletin's headline names a Gogs 10.0 RCE and an n8n workflow-to-RCE among the week's items.
A new Grandoreiro malware campaign abuses the legitimate Duplicate Files Finder (DFF) application to run malicious code via DLL sideloading; per Acronis telemetry, activity remains concentrated in Latin America, with Mexico, Spain, Peru and Argentina accounting for the largest share of infections.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-outlet relay of vendor research; no primary report or vendor response
Every claim is attributed to a named source (Check Point researcher Jiri Vinopal, Acronis, DoJ, State Department) and quoted directly, which is better than anonymous assertion. But the cluster contains exactly one publisher, no link to the underlying Check Point technical write-up, no CVE or patch identifier, no Microsoft comment on whether BTR.sys abuse is mitigated, and no reproducible detail on the boot-time golden window. The espionage and malware items are secondary summaries of other parties' documents rather than independently verified reporting.
Technique demonstrated, not observed in use; adjacent campaigns are live
For the headline BTR.sys technique the only observation is a research disclosure with a weaponisation tool; no supplied source reports real-world exploitation, deployment, or defender detections. Real-world activity in the cluster belongs to the adjacent items: an active Grandoreiro sideloading campaign with Acronis infection telemetry, and a historical Iranian espionage campaign now at the indictment stage. Adoption is therefore low for the story's core assertion even though the surrounding week shows genuine operational activity.
Capability framed as an existing bypass; no exploitation or mitigation status shown
The dek's flat statement that signature-based blocking does not apply is a faithful relay of the researcher's quote, and the underlying finding is meaningful. Overstatement comes from what is absent: no evidence anyone is using this, no Microsoft position on whether the driver is blocklisted or the golden window closed, and the boot-time precondition (attacker capability to influence early start) is not spelled out. The espionage and Grandoreiro items are reported in measured terms with concrete figures, which limits the gap.
Endpoint and exposure-management vendors supply both the finding and the trend framing
Check Point authored the BTR.sys research and separately provided the interpretive quote that commercially-run espionage contractors are 'the trend to watch' - both directions favour demand for the endpoint and exposure-management products it sells. Acronis supplies the Grandoreiro telemetry. None of these incentives is disclosed or examined in the coverage. The DoJ and State Department material is government-sourced with its own deterrence and prosecutorial motives, plainly labelled as charges.
Named attributions, but one publisher and no corroboration
Claims are specific and attributed, which supports moderate confidence in what was said. Confidence is capped by the single-publisher cluster, the absence of the primary Check Point report, no Microsoft or independent confirmation of the kernel technique, and a roundup format that offers no room for verification. The DoJ-derived numbers are the most reliable elements; the technical bypass claim is the least corroborated.
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
build
Notion's agent stack is live, not slideware, and it only changes one of your decisions1 distinct publisher
product
State Department letter would make 35 countries pick an AI side, and the workaround already exists1 distinct publisher
build
Amazon Q executed code from any repo you opened, and it is not the only one1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026