← Back to driver explorer
Driver intelligenceMaliciousVerified

reddriver.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / 87593c63-9e3e-4d09-aa47-94bca0783396ADDED / 2023-07-12AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

reddriver.sysSample 1 · HVCI TRUE
MD5
cd2c641788d5d125c316ed739c69bb59
SHA1
86e6669dbbce8228e94b2a9f86efdf528f0714fd
SHA256
82b0e1d7a27b67f0e6dc39dc41e880bdaef5d1f69fcec38e08da2ed78e805ef9
Imphash
e3ee9131742bf9c9d43cb9a425e497dd
Authentihash MD5
83a03ceabf6f3e51d5f5016cbea4759d
Authentihash SHA1
e341a86e685c120f023bc2f313e220a6934f8767
Authentihash SHA256
7aa067d928404795b4eb9c169639f23997227504ca4eb7b5b21518e6155abd47
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create reddriver.sys binPath=C:\windows\temp\reddriver.sys type=kernel && sc.exe start reddriver.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references