Threat Brief — 2026-08-02 — Drivers, Hijackers, and Handlers
Executive summary. The SilverFox campaign resurfaces with fresh technical detail on how three vulnerable Windows drivers are being weaponised to kill antivirus and seize endpoint control. Google is preparing a Chrome feature to block policy-installed extensions from hijacking the New Tab page — a welcome hardening against enterprise-tier adware. Separately, Iranian intelligence handlers are reportedly assigning collection tasks to recruits directly via Telegram, including during ambulance shifts, marking an escalation in operational tradecraft.
Top items
- SilverFox campaign evolves: three vulnerable Windows drivers used to disable antivirus and gain full endpoint control. New breakdown reveals the attack chain starts from a routine file delivery and leverages three separately vulnerable kernel drivers to dismantle endpoint protection before establishing persistent control. This extends the story first reported 2026-07-30 by RSS:anquanke. Organisations relying on managed Windows endpoints should audit driver allow-lists and review EDR tamper-protection posture. (src: securitylab-ru)
- Google Chrome prepares default blocking of New Tab hijacker extensions. A forthcoming Chrome security feature would prevent policy-installed extensions from overriding the New Tab page or changing the default search engine — a common abuse vector for enterprise-deployed adware and search-hijacking extensions. If shipped, this would reduce a persistent low-level threat to managed browser fleets without requiring admin intervention. (src: BleepingComputer)
- Iranian intelligence handlers assign operational tasks via Telegram, including during ambulance shifts. Recruits are being tasked to collect imagery and information directly through Telegram channels, with at least one case resulting in a criminal prosecution from a handful of photographs. This signals a shift toward more hands-on, real-time tasking by Iranian handlers rather than passive recruitment. (src: securitylab-ru)
Themes
Driver-based defence evasion remains a live problem. The SilverFox update reinforces a pattern seen across multiple campaigns this year: attackers increasingly rely on legitimately signed but vulnerable kernel drivers to disable security tooling rather than writing custom rootkits. Restricting driver loading via WDAC or similar policies continues to be the most effective mitigation.
Messaging platforms as operational infrastructure. Telegram-based tasking by Iranian handlers echoes broader trends in platform-mediated recruitment and C2 — a pattern also visible in the Europol child-recruitment network reported last week. Securing or monitoring employee presence on consumer messaging platforms remains difficult but increasingly relevant for organisations in sensitive sectors.
