LcTkA.sys
SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005. This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
LcTkA.sysSample 1 · HVCI FALSE
- MD5
909f3fc221acbe999483c87d9ead024a- SHA1
b2f955b3e6107f831ebe67997f8586d4fe9f3e98- SHA256
c8f9e1ad7b8cce62fba349a00bc168c849d42cfb2ca5b2c6cc4b51d054e0c497- Imphash
ce10082e1aa4c1c2bd953b4a7208e56a- Authentihash MD5
b663d79a688800d84065ccc2809874b7- Authentihash SHA1
46a9d9e9904ba5f4c011ad69d0795969c721c662- Authentihash SHA256
675329ef7a63a7c58d3daa6cb5c6e299143decec7a149c36a6bfe204bbf0407e- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create LcTkA.sys binPath=C:\windows\temp\LcTkA.sys type=kernel && sc.exe start LcTkA.sysElevate privileges · Privileges: kernel · OS: Windows 10

