https://thehackernews.com/2024/05/ghostengine-exploits-vulnerable-drivers.html
GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking Attack
New cryptojacking campaign REF4578 discovered. Hackers use vulnerable drivers to disable security solutions and install XMRig miner.
exploitsvulnerabledriversdisablecryptojacking