The technique
The variant abuses a legitimately signed but vulnerable driver (a "bring your own vulnerable driver" attack) to terminate Defender and other security agents from kernel space before encryption begins.
What to check now
- Confirm tamper protection is enabled on Defender and your EDR
- Enable Microsoft's vulnerable driver blocklist
- Alert on security-service stop events and unexpected driver loads
- Verify your EDR reports to a console the attacker can't reach from the endpoint