BTR.sys weaponisation (BTR Reforged)
tool · tool:btr-sys-loldriver-primitive
Technique documented by Check Point Research on 2026-08-20 that repurposes BTR.sys, Microsoft Defender's own signed boot-time remediation driver embedded in MpEngine.dll, into a general-purpose kernel-mode file and registry primitive. Configuration is delivered as an encrypted blob in an NTFS alternate data stream on the driver file, and six action types include arbitrary file write and arbitrary registry write. No CVE was assigned; MSRC declined servicing because the technique requires pre-existing administrative privilege. Check Point observed no real-world abuse.
Aliases: BTR Reforged, Boot Time Removal Tool abuse
Coverage
1
first 2026-08-23 → last 2026-08-23
Latest activity
2026-08-23
No exploit, no vulnerability, nothing to blocklist; the driver is a required Defender component, and its…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, energy, water · regions: europe
Sources cited
2
2 hosts
Action items (1)
Do-now tasks recorded on the entries about BTR.sys weaponisation (BTR Reforged), newest first. Check the date before acting on an older one.
- Enumerate which accounts and groups hold SeLoadDriverPrivilege across your Windows estate and remove it wherever it is not required; it is the sole precondition for this technique and the only control Microsoft's servicing decision leaves you.2026-08-23No exploit, no vulnerability, nothing to blocklist…
Defender insights
What each entry about BTR.sys weaponisation (BTR Reforged) tells a defender to do, newest first.
Triage · detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (6 across 4 tactics)
6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- PersistenceModify Registry · Create or Modify System Process: Windows Service · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationCreate or Modify System Process: Windows Service · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information · Hide Artifacts: NTFS File Attributes
- Defense ImpairmentModify Registry · Disable or Modify Tools
Persistence TA0003
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
Privilege Escalation TA0004
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
T1564.004Hide Artifacts: NTFS File Attributes×1
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
Defense Impairment TA0112
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗
Entries about BTR.sys weaponisation (BTR Reforged) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- research.checkpoint.com1 (50%)
- thehackernews.com1 (50%)