mbamchameleon.sys
Malwarebytes' mbamchameleon.sys 3.2.0.456 exposes process termination to verified, registered client processes. The reported Bring Your Own Trusted Caller technique abuses administrator-level control of a genuine signed Malwarebytes client: the driver's on-disk image verification does not attest to the integrity of code executing inside that client. Static analysis confirms client verification and registration through IOCTL 0x222008 and a current-process client-state gate before IOCTL 0x222024 reaches ZwTerminateProcess for a supplied process identifier. An unrelated unsigned process does not meet those checks. The driver must be loaded and the caller must execute inside a verified, registered client. This record is limited to the reviewed sample and does not assert that all current product versions are affected.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
mbamchameleon.sysSample 1 · HVCI unknown
- MD5
1258a8e1beab105aa96c93aa34dd9ef8- SHA1
a435a462a0976135e2257b46e52b576fabac3d34- SHA256
d86b9b20788b6bff70a1a4c4111b2ea33b9ec705cc6b8fe869362fc3899820a3- Imphash
9f4ab3bb8a1adfb8e5bebea149d4e25c- Authentihash MD5
8dc1927fadf434f857e62d0d1e130696- Authentihash SHA1
51d336ef7563a3377a5f8d9b8917b7dfbe115350- Authentihash SHA256
69e1de5800cd3fc5b7f37c5babcb0888b7fc152557251d507f735bcf7f697430- Machine
- AMD64
- Version
- 3.2.0.456
- Publisher
- Malwarebytes
Research & references
Acknowledgement: Xusheng Li @xusheng6

