Skip to main content
← All Articles

Tag

#BYOVD

7 articles

Advertisement

Bypassing Hardware Gates: Exploitability of Vulnerable Drivers
HIGH
Threat Intel

Bypassing Hardware Gates: Exploitability of Vulnerable Drivers

Technical analysis of how researchers bypass hardware-gating to exploit Windows kernel-mode drivers without physical devices in BYOVD attacks.

Runtime Rebel Intel
4 min read·May 22, 2026
Combatting EDR-Killer Tools and BYOVD Attack Techniques
HIGH
Threat Intel

Combatting EDR-Killer Tools and BYOVD Attack Techniques

Defenders face new challenges as the EDR-killer ecosystem expands, utilizing Bring Your Own Vulnerable Driver (BYOVD) to disable security agents.

Runtime Rebel Intel
3 min read·Apr 15, 2026
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
CRITICAL
Malware

Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD

Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.

Runtime Rebel Intel
3 min read·Apr 6, 2026
Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions
CRITICAL
Threat Intel

Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions

U.S. taxpayers targeted by malvertising campaign delivering ScreenConnect and HwAudKiller to disable security software via vulnerable Huawei drivers.

Runtime Rebel Intel
4 min read·Mar 24, 2026
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
HIGH
Malware

54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers

Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.

Runtime Rebel Intel
3 min read·Mar 19, 2026
TH
HIGH
Threat Intel

Russian-Speaking Actor Uses BlackSanta EDR Killer Against HR Teams

Russian-speaking actors use BlackSanta malware to target HR departments, employing BYOVD techniques to disable EDR and facilitate network compromise.

Runtime Rebel Intel
3 min read·Mar 11, 2026
BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement
HIGH
Malware

BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement

An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining yield.

Runtime Rebel Intel
2 min read·Feb 23, 2026