← Back to driver explorer
Driver intelligenceMaliciousVerified

hlpdrv.sys

hlpdrv.sys is a malicious driver used to disable Windows Defender by modifying registry settings. This driver has been observed in Akira ransomware campaigns, where it is deployed to facilitate AV/EDR evasion or disablement through a Bring Your Own Vulnerable Driver (BYOVD) exploitation chain. The malware modifies the DisableAntiSpyware registry key via regedit.exe execution. In observed intrusions it is dropped to the user %TEMP% folder (C:\Users\<user>\AppData\Local\Temp\hlpdrv.sys) and registered as service KMHLPSVC alongside ThrottleStop.sys dropped as rwdrv.sys (service mgdsrv).

UUID / 73bd234a-6c4f-4304-9e7d-5bc7a3f263e2ADDED / 2025-10-27AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

hlpdrv.sysSample 1 · HVCI unknown
MD5
cf7cad39407d8cd93135be42b6bd258f
SHA1
ce1b9909cef820e5281618a7a0099a27a70643dc
SHA256
bd1f381e5a3db22e88776b7873d4d2835e9a1ec620571d2b1da0c58f81c84a56
Imphash
bb62d5bfbc06bfc0791bfc589467b350
Authentihash MD5
3e1467f89f1d0e6ff341afd460b61997
Authentihash SHA1
7be5524927a472e0d6fbb80767fdf1ff1aa4dffc
Authentihash SHA256
a22d5d42dd0cdae016b536799ab9c384c23b42f5662f0b115b3b85ccb9e23242
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create KMHLPSVC binPath=C:\windows\temp\hlpdrv.sys type=kernel && sc.exe start KMHLPSVC

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: GuidePoint Research and Intelligence Team (GRIT) @GuidepointSec