
Once decrypted, the configuration contains a sequence of actions like file deletion, directory deletion, file moves, and registry operations. Registry operations found possible included deleting registry keys and values, setting registry values, arbitrary registry modification, and, potentially, persistence or security control tampering.
When the destination is set to System32, the file-move primitive can become an arbitrary file-write capability, Vinopal noted.
The abuse was automated with BTR_CLI, including the extraction of the legitimate driver from the local Defender installation, construction of the encrypted transaction, and loading the driver. Using the target machine’s own copy of BTR.sys, the tool avoids introducing external drivers as with conventional BYOVD attacks, CPR noted.
