← Back to driver explorer
Driver intelligenceMaliciousVerified

SakDriver.sys

SakDriver is a malicious Windows kernel rootkit analyzed by 0xSec. It uses a registry callback for command dispatch and process-memory manipulation, conceals its driver file and service registry entries, and hides network connections through an NSI hook. It also implements WFP destination filtering and HTTP reporting. The sample uses the device name \Device\SakDriverWFP and carries a CrackerDrv.pdb path. These findings apply to the analyzed sample; current Windows loadability and HVCI compatibility have not been established.

UUID / 7d9e8ee4-6725-4216-bc6b-ac3042018d5cADDED / 2026-09-16AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

SakDriver.sysSample 1 · HVCI unknown
MD5
b5f122f3f07f618c0a7678fa40801faa
SHA1
7440358c5041eba34e8673100989df756a6426da
SHA256
4e95aba17c1a423cda5cc9f9f04f7cf8db17e294eb31ed1aa85063601b82fe8d
Imphash
7afd4d4bb61395a3cd7d1b040e1cfd9b
Authentihash MD5
c151927ea37d72f1f08ccdc94ba37524
Authentihash SHA1
a13988ece3adc1f1cb5166cd48abd32050d8540d
Authentihash SHA256
47b766019e0e18251ba39e24d20a99f45bdd5c310a4e94091e4f19d9fef27996
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Research & references

Acknowledgement: 0xSec