<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #BYOVD</title><description>Cybersecurity articles tagged #BYOVD on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits</title><link>https://runtimerebel.com/blog/spectre-malware-uat-10147-targets-iis-linux-servers-with-rootkits</link><guid isPermaLink="true">https://runtimerebel.com/blog/spectre-malware-uat-10147-targets-iis-linux-servers-with-rootkits</guid><description>Chinese-speaking actor UAT-10147 deploys SPECTRE, a cross-platform implant featuring Linux rootkit and BYOVD EDR bypass capabilities.</description><pubDate>Thu, 20 Aug 2026 16:27:35 GMT</pubDate><category>Malware</category><category>Linux Rootkit</category><category>BYOVD</category><category>UAT 10147</category><category>SPECTRE</category></item><item><title>GodDamn Ransomware Leverages Signed Driver to Disable EDR</title><link>https://runtimerebel.com/blog/goddamn-ransomware-leverages-signed-driver-to-disable-edr</link><guid isPermaLink="true">https://runtimerebel.com/blog/goddamn-ransomware-leverages-signed-driver-to-disable-edr</guid><description>Analysis of GodDamn ransomware&apos;s BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.</description><pubDate>Thu, 09 Jul 2026 11:03:47 GMT</pubDate><category>GodDamn Ransomware</category><category>BYOVD</category><category>Kernel Driver</category><category>EDR Evasion</category><category>Microsoft Signed Driver</category><category>Ransomware</category></item><item><title>CVE-2025-5777: Anubis Ransomware Exploits Citrix Bleed 2</title><link>https://runtimerebel.com/blog/cve-2025-5777-anubis-ransomware-exploits-citrix-bleed-2</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-5777-anubis-ransomware-exploits-citrix-bleed-2</guid><description>Anubis ransomware affiliates exploit Citrix Bleed 2 (CVE-2025-5777) and BYOVD techniques to breach networks via RMM tools and supply chain credentials.</description><pubDate>Fri, 03 Jul 2026 07:24:55 GMT</pubDate><category>CVE-2025-5777</category><category>Anubis Ransomware</category><category>Citrix NetScaler</category><category>BYOVD</category><category>RMM Abuse</category></item><item><title>Bypassing Hardware Gates: Exploitability of Vulnerable Drivers</title><link>https://runtimerebel.com/blog/bypassing-hardware-gates-exploitability-of-vulnerable-drivers</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-hardware-gates-exploitability-of-vulnerable-drivers</guid><description>Technical analysis of how researchers bypass hardware-gating to exploit Windows kernel-mode drivers without physical devices in BYOVD attacks.</description><pubDate>Fri, 22 May 2026 12:59:07 GMT</pubDate><category>BYOVD</category><category>Windows Kernel</category><category>Driver Security</category><category>Privilege Escalation</category><category>Kernel Exploitation</category></item><item><title>Combatting EDR-Killer Tools and BYOVD Attack Techniques</title><link>https://runtimerebel.com/blog/combatting-edr-killer-tools-and-byovd-attack-techniques</link><guid isPermaLink="true">https://runtimerebel.com/blog/combatting-edr-killer-tools-and-byovd-attack-techniques</guid><description>Defenders face new challenges as the EDR-killer ecosystem expands, utilizing Bring Your Own Vulnerable Driver (BYOVD) to disable security agents.</description><pubDate>Wed, 15 Apr 2026 00:46:31 GMT</pubDate><category>BYOVD</category><category>EDR Killer</category><category>Kernel Security</category><category>Endpoint Protection</category><category>Driver Exploitation</category></item><item><title>Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD</title><link>https://runtimerebel.com/blog/qilin-and-warlock-ransomware-bypass-300-edr-tools-via-byovd</link><guid isPermaLink="true">https://runtimerebel.com/blog/qilin-and-warlock-ransomware-bypass-300-edr-tools-via-byovd</guid><description>Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.</description><pubDate>Mon, 06 Apr 2026 12:23:52 GMT</pubDate><category>Qilin</category><category>Warlock</category><category>BYOVD</category><category>EDR Bypass</category><category>Ransomware</category></item><item><title>Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions</title><link>https://runtimerebel.com/blog/tax-search-malvertising-deploys-hwaudkiller-to-blind-edr-solutions</link><guid isPermaLink="true">https://runtimerebel.com/blog/tax-search-malvertising-deploys-hwaudkiller-to-blind-edr-solutions</guid><description>U.S. taxpayers targeted by malvertising campaign delivering ScreenConnect and HwAudKiller to disable security software via vulnerable Huawei drivers.</description><pubDate>Tue, 24 Mar 2026 20:18:52 GMT</pubDate><category>Malvertising</category><category>HwAudKiller</category><category>Screenconnect</category><category>BYOVD</category><category>Google Ads</category></item><item><title>54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers</title><link>https://runtimerebel.com/blog/54-edr-killers-use-byovd-to-abuse-34-signed-drivers</link><guid isPermaLink="true">https://runtimerebel.com/blog/54-edr-killers-use-byovd-to-abuse-34-signed-drivers</guid><description>Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.</description><pubDate>Thu, 19 Mar 2026 20:15:35 GMT</pubDate><category>BYOVD</category><category>EDR Killer</category><category>Ransomware</category><category>Kernel Exploitation</category><category>Windows Security</category></item><item><title>Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis</title><link>https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</guid><description>The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.</description><pubDate>Tue, 17 Mar 2026 16:31:42 GMT</pubDate><category>Warlock Ransomware</category><category>BYOVD</category><category>EDR Evasion</category><category>Lateral Movement</category><category>Post Exploitation</category></item><item><title>Russian-Speaking Actor Uses BlackSanta EDR Killer Against HR Teams</title><link>https://runtimerebel.com/blog/russian-speaking-actor-uses-blacksanta-edr-killer-against-hr-teams</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-speaking-actor-uses-blacksanta-edr-killer-against-hr-teams</guid><description>Russian-speaking actors use BlackSanta malware to target HR departments, employing BYOVD techniques to disable EDR and facilitate network compromise.</description><pubDate>Wed, 11 Mar 2026 00:32:05 GMT</pubDate><category>BlackSanta</category><category>EDR Killer</category><category>BYOVD</category><category>HR Targeting</category><category>Russian Speaking Actor</category></item><item><title>BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement</title><link>https://runtimerebel.com/blog/byovd-driven-xmrig-campaign-employs-time-based-logic-bombs-and-lateral-movement</link><guid isPermaLink="true">https://runtimerebel.com/blog/byovd-driven-xmrig-campaign-employs-time-based-logic-bombs-and-lateral-movement</guid><description>An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining…</description><pubDate>Mon, 23 Feb 2026 20:18:27 GMT</pubDate><category>XMRig</category><category>BYOVD</category><category>Cryptojacking</category><category>Persistence</category><category>Wormable</category></item></channel></rss>