← Back to driver explorer
Driver intelligenceVulnerableVerified

mbamchameleon.sys

Malwarebytes' mbamchameleon.sys 3.2.0.456 exposes process termination to verified, registered client processes. The reported Bring Your Own Trusted Caller technique abuses administrator-level control of a genuine signed Malwarebytes client: the driver's on-disk image verification does not attest to the integrity of code executing inside that client. Static analysis confirms client verification and registration through IOCTL 0x222008 and a current-process client-state gate before IOCTL 0x222024 reaches ZwTerminateProcess for a supplied process identifier. An unrelated unsigned process does not meet those checks. The driver must be loaded and the caller must execute inside a verified, registered client. This record is limited to the reviewed sample and does not assert that all current product versions are affected.

UUID / c2feb6de-46fe-44ab-93c2-634ea6ab83a2ADDED / 2026-09-18AUTHOR / Xusheng Li, Michael Haag

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

mbamchameleon.sysSample 1 · HVCI unknown
MD5
1258a8e1beab105aa96c93aa34dd9ef8
SHA1
a435a462a0976135e2257b46e52b576fabac3d34
SHA256
d86b9b20788b6bff70a1a4c4111b2ea33b9ec705cc6b8fe869362fc3899820a3
Imphash
9f4ab3bb8a1adfb8e5bebea149d4e25c
Authentihash MD5
8dc1927fadf434f857e62d0d1e130696
Authentihash SHA1
51d336ef7563a3377a5f8d9b8917b7dfbe115350
Authentihash SHA256
69e1de5800cd3fc5b7f37c5babcb0888b7fc152557251d507f735bcf7f697430
Machine
AMD64
Version
3.2.0.456
Publisher
Malwarebytes

Research & references

Acknowledgement: Xusheng Li @xusheng6