Ransomware uses vulnerable, signed driver to disable endpoint security
New tactics for ransomware attackers. Thanks to outdated drivers, they turn off disturbing security by sending malicious ones. At the same time, it kills processes and files that belong to Windows security.
https://www.helpnetsecurity.com/2020/02/10/ransomware-signed-driver/