{"id":5773,"date":"2025-07-31T10:04:54","date_gmt":"2025-07-31T10:04:54","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/31\/qilin-ransomware-leverages-tpwsav-sys-driver-to-disable-edr-security-measures\/"},"modified":"2025-07-31T10:04:54","modified_gmt":"2025-07-31T10:04:54","slug":"qilin-ransomware-leverages-tpwsav-sys-driver-to-disable-edr-security-measures","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/31\/qilin-ransomware-leverages-tpwsav-sys-driver-to-disable-edr-security-measures\/","title":{"rendered":"Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures"},"content":{"rendered":"<p>    Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals have once again demonstrated their evolving sophistication by weaponizing an obscure Toshiba laptop driver to bypass endpoint detection and response systems.<\/p>\n<p>The Qilin ransomware operation, active since July 2022, has incorporated a previously unknown vulnerable driver called TPwSav.sys into their attack arsenal, enabling them to stealthily disable EDR protections through a technique known as bring-your-own-vulnerable-driver (BYOVD).<\/p>\n<p>This development represents a significant escalation in ransomware operators\u2019 ability to evade traditional security measures that organizations have come to rely upon.<\/p>\n<p>The Qilin ransomware group operates under a ransomware-as-a-service model, offering affiliates substantial profit margins of 80% for ransom payments under $3 million and 85% for larger payments.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh_cjRgJg3BaJKvp9GLUp4ofgKluOgZWsnTFZJEHnITXkS8QHSRJksRN6SpbqOrwzc_qId6cuFi08vHCowMNGyCY6sjGx4ELij9R7bEUQp16pYRmdzyDVAEZIqkNi-kJLM8ZSaaiJz3PjeesxEZN0OVbJNxs5vrgTGxgn6y2yLlussd5H07275HBXnYCyc\/s16000\/Qilin%2520affiliates%2520have%2520been%2520observed%2520gaining%2520initial%2520access%2520via%2520social%2520engineering%2520attacks%2520%28Source%2520-%2520Blackpoint%2520Cyber%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Qilin affiliates have been observed gaining initial access via social engineering attacks (Source \u2013 Blackpoint Cyber)<\/figcaption><\/figure>\n<\/div>\n<p>Written in both Golang and Rust programming languages, <a href=\"https:\/\/cybersecuritynews.com\/hc3-unveils-qilin-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Qilin<\/a> targets Windows and Linux systems through a double extortion methodology, stealing and threatening to leak victim data if ransom demands are not met.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiEpJb5olFTBAzAlm9tnwmsPF2wtScDsN3gTDOh-oA0y_4CO6iRdZ1AxUcYczLj7ysmjl4mDQnR-cPhqEH1e5t8nAxo7-rNpJLQ38KsUAcjLyWf8cig-ZHgHPo6RKlmu1Xs3sW0ufXNPWDaeLUcNlEKST2aFxaoMruXffz2cpNAZlRts1EFU4S5gFbx9dU\/s16000\/Qilin%2520ransom%2520note%2520%28Source%2520-%2520Blackpoint%2520Cyber%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Qilin ransom note (Source \u2013 Blackpoint Cyber)<\/figcaption><\/figure>\n<\/div>\n<p>The group maintains strict operational security by prohibiting attacks against Commonwealth of Independent States countries, a common practice among Russian-speaking cybercriminal organizations.<\/p>\n<p>Blackpoint analysts <a href=\"https:\/\/blackpointcyber.com\/blog\/qilin-ransomware-and-the-hidden-dangers-of-byovd\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this sophisticated attack chain during a recent incident investigation, where the ransomware operators demonstrated advanced kernel-level manipulation capabilities.<\/p>\n<p>The attack sequence begins with the deployment of a legitimate signed executable named upd.exe, which is actually the Carbon Black Cloud Sensor AV update tool.<\/p>\n<p>However, instead of loading its legitimate counterpart, the executable sideloads a malicious dynamic link library called avupdate.dll, which serves as the initial payload delivery mechanism.<\/p>\n<p>The malicious DLL contains an exported function called avupdate_get_version that performs multiple <a href=\"https:\/\/cybersecuritynews.com\/new-xworm-v6-variants-with-anti-analysis-capabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">anti-analysis<\/a> techniques, including virtual machine detection and debugging checks, before loading and executing an encoded file named web.dat.<\/p>\n<p>This file represents a Windows portable executable that has been XOR-encoded with the byte value 0x6a, demonstrating the attackers\u2019 commitment to obfuscating their tools throughout the infection chain.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Kernel-Level EDR Bypass Mechanism<\/strong><\/h2>\n<p>The decoded web.dat file reveals itself as a heavily customized variant of EDRSandblast, an open-source tool designed to disable EDR products at the kernel level.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihBxMKDUf8DQYaI2fV6ofkLSe3-WKHu3CW7J8d1o2iRj9_HAAdf1gFb-9dWc9AGZSbdfBBsitAPPhFEsPtEY8HJ5yIejJG0j4OaxKMXfTNoKCs-nwqcYkMzWQ1DQMQx6CJbiDgEj5JSrNv2sylB_jGqI1JhkOvTK0BxKxK2Oqf2uQe1PrgOzHzCSBAo-0\/s16000\/EDRSandblast%2520loading%2520TPwSav.sys%2520%28Source%2520-%2520Blackpoint%2520Cyber%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">EDRSandblast loading TPwSav.sys (Source \u2013 Blackpoint Cyber)<\/figcaption><\/figure>\n<\/div>\n<p>Rather than using commonly detected vulnerable drivers that most EDR vendors have flagged, the threat actors strategically selected TPwSav.sys, a legitimate signed Windows kernel driver originally developed for power-saving features on Toshiba laptops and compiled in 2015.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEib18kaHYYXrdzIIY7rpQHgxjNQNYc_COVfQgkHEBcXsv-lgIv0e-qP6XvRQ2OJDqBi1t5e892D0NOBFw9b63QO4CFi6378q69AoTYuKhKECN3dwa2c9uvAd-_NEVdccDhBmZWkBI8IldMfe67pjaHIbef3pYg7Wm9ZeW59xvKmRDHXR7T8WJePtkyrr7M\/s16000\/Vulnerable%2520functions%2520in%2520TPwSav.sys%2520%28Source%2520-%2520Blackpoint%2520Cyber%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Vulnerable functions in TPwSav.sys (Source \u2013 Blackpoint Cyber)<\/figcaption><\/figure>\n<\/div>\n<p>The TPwSav.sys driver contains two critical IO control codes that enable arbitrary memory reading and writing operations, one byte at a time.<\/p>\n<p>These IOCTL handlers map physical memory addresses to virtual addresses using the MmMapIoSpace function, allowing the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> to read or modify memory contents before unmapping the address with MmUnmapIoSpace.<\/p>\n<p>This capability enables the attackers to bypass read-only memory protections by leveraging physical addresses to map and modify virtual address contents.<\/p>\n<p>The attack employs a sophisticated technique where the BeepDeviceControl function in the native Windows driver Beep.sys is overwritten with custom shellcode.<\/p>\n<p>This hijacking process involves enumerating essential addresses, including Beep\u2019s base address and the BeepDeviceControl offset, while retrieving virtual-to-physical address mappings through SystemSuperfetchInformation queries.<\/p>\n<p>Once the shellcode replaces the legitimate handler, it implements a custom IOCTL processor that responds to the command 0x222000, providing unrestricted kernel memory access capabilities that effectively neutralize most <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">EDR solutions<\/a> by removing kernel callback routines and event tracing mechanisms.<\/p>\n<p>The successful integration of TPwSav.sys into the Qilin operation\u2019s toolkit demonstrates the increasing sophistication of ransomware affiliates and their access to advanced tools through dark web marketplaces, highlighting the urgent need for enhanced detection mechanisms beyond traditional EDR solutions.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Integrate\u00a0<strong>ANY.RUN TI Lookup<\/strong>\u00a0with your SIEM or SOAR To Analyses Advanced Threats<\/strong>\u00a0-&gt;\u00a0<strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=atricle&amp;utm_campaign=want-to-detect-incidents-before&amp;utm_content=plans1&amp;utm_term=290725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try 50 Free Trial Searches<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/qilin-ransomware-leverages-tpwsav-sys-driver\/\">Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/qilin-ransomware-leverages-tpwsav-sys-driver\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures Cybercriminals have once again demonstrated their evolving sophistication by weaponizing an obscure Toshiba laptop driver to bypass endpoint detection and response systems. The Qilin ransomware operation, active since July 2022, has incorporated a previously unknown vulnerable driver called TPwSav.sys into their attack arsenal, enabling them [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5773","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5773"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5773"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5773\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5773"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5773"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}