throttlestop.sys
ThrottleStop is developed by TechPowerUp and is designed to monitor for and correct CPU throttling issues. However, Kaspersky researchers from the Global Emergency Response Team (GERT) found out that it is being abused by attackers to terminate defense mechanisms. Akira ransomware affiliates have dropped this same signed driver (same SHA256) as rwdrv.sys in %TEMP% and registered it as a kernel service named mgdsrv, alongside the malicious hlpdrv.sys (service KMHLPSVC), to disable Microsoft Defender. Note that the rwdrv.sys filename collides with the unrelated RWEverything RwDrv.sys driver, so name-based hunting will conflate the two; hunt on hash or the TechPowerUp LLC signer instead. Per the public CVE-2025-7771 PoC write-up, the driver derives its device name from the service name, so device-name based detections are also unreliable. IronChain ransomware also bundles this driver and configures IOCTL 0x8000649C, but per ANY.RUN's static analysis never sends it.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
throttlestop.sysSample 1 · HVCI unknown
- MD5
6bc8e3505d9f51368ddf323acb6abc49- SHA1
82ed942a52cdcf120a8919730e00ba37619661a3- SHA256
16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f0- Imphash
bed949fc01017d391d1b5808755a7fd1- Authentihash MD5
c89a0c0aa99c8bed0f5c7eec6282f421- Authentihash SHA1
77badfeebc7f448e6b8a52dcf15f48506a0e9a58- Authentihash SHA256
51ad864af75441b537ab0a37cf045f19117eab5e10fc179ef1e8164d9ef5d2e0- Machine
- AMD64
- Version
- 3.0.0.0
- Publisher
- Not recorded
Recorded command
sc.exe create throttlestop.sys binPath= C:\windows\temp\throttlestop.sys type=kernel && sc.exe start throttlestop.sysElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
- https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/
- https://www.cve.org/CVERecord?id=CVE-2025-7771
- https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/
- https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
- https://github.com/enessakircolak/CVE-2025-7771
- https://any.run/cybersecurity-blog/ironchain-analysis/

