
| Names | Cahnadr NDriver | |
| Category | Malware | |
| Type | Rootkit | |
| Description | (Kaspersky) Canhadr, also known as NDriver, contains low-level routines for network, IO operations and so on. Its kernel-mode program is able to execute malicious code without crashing the whole file system or causing Blue Screen – a remarkable achievement. Written in pure C language, Canhadr/Ndriver provides full access to the hard drive and operating memory despite device security restrictions, and carries out integrity control of various system components to avoid debugging and security detection. | |
| Information | <https://securelist.com/apt-slingshot/84312/> | |
Last change to this tool card: 20 April 2020
Download this tool card in JSON format
Previous: Cadelspy
Next: Cain & Abel
| Changed | Name | Country | Observed | ||
APT groups | |||||
| Slingshot | [Unknown] | 2012 | |||
1 group listed (1 APT, 0 other, 0 unknown)
|
Digital Service Security Center Follow us on |
Report incidents |
|
| +66 (0)2-123-1227 | ||
| [email protected] | ||