As TomsHardware points out, that driver still has a valid Verisign certificate....
https://www.news.sophos.com/en-us/2020/02/06/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software/