TrueSight Driver Exploited to Avoid Windows Security

22 Jan 2026

Hackers have weaponized the TrueSight driver to disable Windows security tools before deploying ransomware and malware. This wide-scale attack involves bypassing protections to disable endpoint detection and response (EDR) and antivirus solutions across Windows systems, using legitimate drivers named truesight.sys from Adlice Software.

Massive Driver Abuse

Researchers from Check Point and MagicSword have noted the exploitation of TrueSight drivers has become a common strategy among various threat groups. The campaign uses over 2,500 signed driver variants to evade detection. Despite being signed with legacy certificates, these drivers run with full privileges, disabling security systems in the process. Affected systems include modern Windows 11 machines, where the drivers, when loaded, terminate key security processes without raising alerts.

Global Reach and Methodology

The abuse of TrueSight is not limited to one group or region. Both financially motivated attackers and advanced persistent threat (APT) groups are employing the method to deliver ransomware and remote access Trojans. Attackers initiate the attack typically through phishing, leading to a disguised installer that downloads additional malicious components. The malicious module disables over 200 security products, including Microsoft Defender and Kaspersky, by installing the TrueSight driver as a Windows service. The method allows attackers to execute ransomware with little to no resistance within 30 minutes of initial infiltration.

Impact on Enterprises

The technique's effectiveness is enhanced by the large number of signed driver variants and its high evasion rate against traditional antivirus solutions. This represents a significant risk for enterprises, as the driver can be used to terminate security processes swiftly, enabling the deployment of ransomware such as HiddenGh0st, often going unnoticed until after encryption or data exfiltration.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7420780
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1702384
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
730927
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
491711
downloads

News and reviews for Desktop Windows

TrueSight Driver Exploited to Avoid Windows Security

Hackers misuse TrueSight to bypass Windows security tools, leading to ransomware deployment.

Read more

Crimson Desert Goes Gold, Release Set for March 19

Crimson Desert has gone gold, set to launch on 2026-03-19. Pearl Abyss confirms the game is ready, promising a rich adventure in Pywel.

Read more

Death Stranding Director's Cut Now on Xbox Game Pass

Death Stranding Director's Cut is now available on Xbox Game Pass for console and PC users, enhancing gameplay options.

Read more

MIO Launches with Unique Metroidvania Experience

MIO debuts with a blend of exploration and combat, offering a new indie Metroidvania experience on The Vessel. Available now for $17.59.

Read more

Windows 11 Update KB5074109 Causes Black Screen Issues

KB5074109 update for Windows 11 leads to black screens, Outlook crashes. Microsoft investigating. Next Patch Tuesday: 2026-02-10.

Read more

Outfit7 Launches PlayValley for PC and Mobile Games

Outfit7 unveils PlayValley, a division for creating PC and mobile games, debuting on Steam by 2026-Q2.

Read more

Arknights: Endfield Launches Globally on 2026-01-22

Arknights: Endfield is set for a global release on January 22, 2026. Preloading is advisable to avoid connectivity issues.

Read more

Cassette Boy Launches on Steam with Engaging Puzzle Mechanics

Cassette Boy debuts on Steam, offering a unique 2D/3D puzzle experience. Explore innovative mechanics and hidden secrets in this engaging game.

Read more

Dune: Awakening Adds Character Transfer Feature

Dune: Awakening update 1.2.40.0 introduces character transfers, enhancing player flexibility and experience.

Read more

Microsoft Expands Game Pass with Major Releases

Microsoft adds major titles like Death Stranding to Game Pass, enhancing the platform's offerings starting 2026-01-21.

Read more