PoisonX is a malicious Windows kernel driver used to disable or weaken endpoint security controls from kernel mode. It is notable for carrying a valid Microsoft Hardware Compatibility signature in observed campaigns, allowing it to load on Windows systems without the friction normally associated with unsigned drivers. Its documented behavior includes terminating security-related processes, stripping user-mode API hooks relied on by endpoint protection products, and in some reporting exposing kernel functionality that can be abused to kill protected security processes. PoisonX has also been described in some campaigns as part of a bring-your-own-vulnerable-driver-style defense-evasion chain, although multiple reports characterize it instead as a purpose-built malicious signed driver rather than a merely vulnerable third-party driver.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PoisonX is a signed Windows kernel driver observed in an April 2026 spear-phishing campaign against organizations in Japan and China.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It dropped a signed kernel driver called PoisonX. PoisonX carries a Microsoft signature, so Windows loads it without complaint. Once active, it kills security processes and strips user-mode API hooks.
この攻撃では、「PoisonX」と呼ばれるカーネルドライバと遠隔操作機能を持つ「10FXRAT(別名:PoisonX RAT)」が悪用されていることを確認しています。
25 distinct techniques documented for this family, organized by ATT&CK tactic.
...the Microsoft-signed PoisonX kernel driver to disable endpoint security through a BYOVD-style defense evasion technique before deploying the ransomware.
その後、ファイル名と同じ名称でWindowsサービスとして登録し、このサービスを起動します。... 「DevCfgCC.sys」というファイル名で永続化ディレクトリへ書き出し、OSの起動時に自動的に読み込まれるよう、システムにサービスとして登録します。
The most notable addition in this GodDamn attack was the PoisonX kernel driver... letting it terminate security processes and strip protective hooks at the kernel level.
マルウェア内部にハードコードされている暗号化された10FXRAT関連ファイル...を、Incremental XORを用いて復号します。
StartPayload resolves APIs dynamically, initializes direct syscall helpers, binds Winsock, and loads any cached plugins from disk.
First, the operators staged a defense-evasion tool disguised as a Symantec product.
これを受け取ったドライバは、WindowsのカーネルAPIや、正規のネットワーク監視ドライバ(¥Driver¥nsiproxy、¥Device¥Tcpなど)をフックし、指定されたPIDのプロセス情報と通信記録をシステムから除外します。これにより、OSのプロセス一覧から自身の存在を消し去り、タスクマネージャーやEDR等の各種システム監視ツールから、プロセスおよびC2サーバとの不正な通信活動を隠蔽することが可能となります。
the signed host side-loads the attacker DLL, which decrypts the bundled cache to stage the driver and RAT.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious Microsoft-signed kernel driver used to kill antivirus/EDR processes, strip security agents of required rights, or tamper with kernel notification records so defenses stop receiving events and go blind.
A malicious Microsoft-signed kernel driver used to disable endpoint defenses by killing security processes and removing user-mode API hooks before ransomware deployment.
Kernel driver used to disable endpoint defenses during the attack prior to final deployment of GodDamn ransomware.
A malicious kernel driver used to disable endpoint defenses, including killing security services such as CrowdStrike Falcon, and used by GodDamn operators for defense evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.