Hackers found a way around Microsoft Defender to install ransomware on PCs, report says

Hey, no fair.
 By 
Alex Perry
 on 
Windows logo on phone screen
Better load up some more antivirus software. Credit: Thomas Fuller/SOPA Images/LightRocket via Getty Images

Windows users should think about reinforcing their antivirus software. And while Microsoft Defender should provide a line of defense against ransomware, a new report claims that hackers have found a way to get around the ransomware tool to infect PCs with ransomware.

A GuidePoint Security report (via BleepingComputer) found that hackers are using Akira ransomware to exploit a legitimate PC driver to load a second, malicious driver that shuts off Windows Defender, allowing for all sorts of monkey business.

The good driver that's being exploited here is called "rwdrv.sys,' which is used for tuning software for Intel CPUs. Hackers abuse it to install "hlpdrv.sys," another driver that they then use to get around Defender — and start doing whatever it is they want to do.


You May Also Like

GuidePoint reported seeing this type of attack starting in the middle of July. It doesn't seem like the loophole has been patched yet, but the more people know about it, the less likely it is for the exploit to work against them, at least in theory.

In the meantime, allow our colleagues at PCMag to recommend some fine third-party antivirus software to you for your Windows PC. For more information on the latest Akira ransomware attacks — including possible defenses — head to GuidePoint Security.

journalist alex perry looking at a smartphone
Alex Perry
Tech Reporter

Alex Perry is a tech reporter at Mashable who primarily covers video games and consumer tech. Alex has spent most of the last decade reviewing games, smartphones, headphones, and laptops, and he doesn’t plan on stopping anytime soon. He is also a Pisces, a cat lover, and a Kansas City sports fan. Alex can be found on Bluesky at yelix.bsky.social.

Mashable Potato

Recommended For You
Iran-linked hackers launch cyberattack against U.S. medtech company Stryker
Stryker logo on medical equipment

Microsoft 365 Outlook down: Microsoft breaks silence on outage
Microsoft logo

Microsoft 365 outage: Outlook is down. What we know.
an illustrated screen with microsoft outage on it

Some Windows 11 PCs can’t shut down after latest update
Windows 11

Upgrade aging PCs with Windows 11 Pro for $12.97
Hands on laptop

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


The Earth is glowing in new Artemis II pictures of home
One half of the Earth is seen floating in space through the open door of the Orion spacecraft.

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!