Skip to main content
← All Articles

Tag

#BYOVD

11 articles

Advertisement

SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits
HIGH
Threat Intel

SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits

Chinese-speaking actor UAT-10147 deploys SPECTRE, a cross-platform implant featuring Linux rootkit and BYOVD EDR bypass capabilities.

Runtime Rebel Intel
5 min read · Aug 20, 2026
GodDamn Ransomware Leverages Signed Driver to Disable EDR
HIGH
Threat Intel

GodDamn Ransomware Leverages Signed Driver to Disable EDR

Analysis of GodDamn ransomware's BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.

Runtime Rebel Intel
4 min read · Jul 9, 2026
CVE-2025-5777: Anubis Ransomware Exploits Citrix Bleed 2
HIGH
Threat Intel

CVE-2025-5777: Anubis Ransomware Exploits Citrix Bleed 2

Anubis ransomware affiliates exploit Citrix Bleed 2 (CVE-2025-5777) and BYOVD techniques to breach networks via RMM tools and supply chain credentials.

Runtime Rebel Intel
3 min read · Jul 3, 2026
Bypassing Hardware Gates: Exploitability of Vulnerable Drivers
HIGH
Threat Intel

Bypassing Hardware Gates: Exploitability of Vulnerable Drivers

Technical analysis of how researchers bypass hardware-gating to exploit Windows kernel-mode drivers without physical devices in BYOVD attacks.

Runtime Rebel Intel
4 min read · May 22, 2026
Combatting EDR-Killer Tools and BYOVD Attack Techniques
HIGH
Threat Intel

Combatting EDR-Killer Tools and BYOVD Attack Techniques

Defenders face new challenges as the EDR-killer ecosystem expands, utilizing Bring Your Own Vulnerable Driver (BYOVD) to disable security agents.

Runtime Rebel Intel
4 min read · Apr 15, 2026
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
HIGH
Malware

Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD

Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.

Runtime Rebel Intel
3 min read · Apr 6, 2026

Advertisement

Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions
HIGH
Threat Intel

Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions

U.S. taxpayers targeted by malvertising campaign delivering ScreenConnect and HwAudKiller to disable security software via vulnerable Huawei drivers.

Runtime Rebel Intel
4 min read · Mar 24, 2026
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
HIGH
Malware

54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers

Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.

Runtime Rebel Intel
3 min read · Mar 19, 2026
Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis
HIGH
Threat Intel

Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis

The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.

Runtime Rebel Intel
3 min read · Mar 17, 2026
HIGH
Threat Intel

Russian-Speaking Actor Uses BlackSanta EDR Killer Against HR Teams

Russian-speaking actors use BlackSanta malware to target HR departments, employing BYOVD techniques to disable EDR and facilitate network compromise.

Runtime Rebel Intel
3 min read · Mar 11, 2026
BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement
MEDIUM
Malware

BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement

An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining…

Runtime Rebel Intel
2 min read · Feb 23, 2026