Threats Tagged 'byovd'
View all threats tagged with 'byovd'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'byovd'
Click on any threat for detailed analysis and mitigation recommendations
The China-nexus threat group Longlegs continues to deploy Warlock ransomware by exploiting Microsoft SharePoint vulnerabilities, particularly the ToolShell exploit chain. Over the past two months, the group targeted at least four organizations including water utilities, telecommunications providers, government bodies, and universities in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. The attackers exploit SharePoint flaws for initial access, use DLL sideloading techniques, abuse vulnerable signed drivers like K7RKScan to disable security software, and leverage Visual Studio Code tunneling for covert remote access. They deploy ransomware at scale by staging payloads in domain SYSVOL shares for rapid network-wide distribution, successfully compromising over 40 hosts in some incidents. Join the discussion | CVE Database V5 | 10/01/2026, 15:37:42 UTC Added: 07/08/2025, 17:09:42 UTC |
Between July and August 2026, a sophisticated phishing campaign targeted organizations in East and Southeast Asia, particularly Japanese entities. The attackers used phishing emails in Japanese and Korean, masquerading as product damage complaints, to lure victims to fake document-sharing websites. These sites delivered ZIP archives containing malware executables with double extensions and DLLs employing advanced loader techniques. The final payloads were consistently from the PureRAT and PureLogs malware families. The campaign used frequent changes in loader structures and multiple evasion techniques to bypass detection. Infrastructure analysis showed commonalities in sending patterns and identifiers across campaigns. Join the discussion | AlienVault OTX General | 09/25/2026, 15:41:27 UTC Added: 09/28/2026, 14:03:04 UTC |
Settra is a ransomware variant first observed in June 2026 that targets organizations through VPNs or compromised credentials. Two incidents were investigated in July and September 2026, affecting the consumer services, retail, and manufacturing sectors. Attackers deployed MeshAgent RMM for persistence, naming ransomware executables after victim domain names. The malicious activity included file encryption with .locked or .locked_wip extensions, deployment of RESTORE_FILES.txt ransom notes, clearing Windows event logs, and disabling Windows recovery options using reagentc and diskpart utilities. One incident featured Bring Your Own Vulnerable Driver (BYOVD) tactics using gdrv.sys. A notable operational security failure occurred when attackers misspelled the Windows Defender Event Log path, preventing its deletion. Both attacks followed remarkably similar operational patterns, with MeshAgent installations pointing to different C2 IP addresses (45.13.122[.]7 and 193.5.65[.]114), and malicious workstation WIN... Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:01 UTC Added: 09/18/2026, 08:46:41 UTC |
Analysis of server infrastructure revealed a complete TukTuk C2 framework (version 2.0) with cross-platform capabilities, including Windows and Linux agents, backend infrastructure, and management panel. The server contained eb.sys matching GentleKiller, along with comprehensive EDR neutralization training materials organized in four progressive lessons covering BYOVD techniques, vulnerable driver hunting, and kernel-level research. DLL sideloading configurations targeting Greenshot, ProcMon, Slack, and Postman were identified. Exfiltrated data included 224 Jira tickets from a global technology company containing information related to U.S. defense organizations and defense contractors, plus credentials from a global healthcare company's Infrastructure-as-Code platform exposing AWS keys, production databases, Azure AD, and Bitbucket access. Join the discussion | AlienVault OTX General | 09/02/2026, 18:24:11 UTC Added: 09/03/2026, 07:52:49 UTC |
A phishing campaign impersonates sales staff from overseas companies, sending emails with malicious GZ compressed files. Extracting these files delivers an injector executable that uses multiple UAC bypass techniques and exploits a vulnerable driver (DCRCVDrv.sys) to disable security products at the kernel level. The injector then uses process hollowing to inject PhantomStealer malware into a legitimate process. PhantomStealer steals sensitive information including keystrokes, screenshots, browser credentials, cryptocurrency wallet data, and manipulates clipboard contents to replace wallet addresses with attacker-controlled ones. Join the discussion | AlienVault OTX General | 08/19/2026, 07:28:55 UTC Added: 08/19/2026, 10:04:41 UTC |
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks. Join the discussion | AlienVault OTX General | 07/20/2026, 09:36:09 UTC Added: 07/20/2026, 11:11:45 UTC |
GodDamn ransomware represents the third iteration of ransomware developed by Hyadina, following Monster (2022) and Beast (2024). A recent attack in June 2026 demonstrates sophisticated tactics including AnyDesk for remote access, NirSoft-based credential harvesting tools, and the PoisonX kernel driver for defense evasion. PoisonX is a malicious driver signed by Microsoft that terminates security processes at the kernel level. Attackers used PsExec for lateral movement, deployed comprehensive credential theft toolkits comprising 14 different tools, and disabled endpoint defenses before encrypting files. The encrypted files were renamed with victim organization names as extensions. The four-day dwell period allowed attackers to stage payloads and conduct reconnaissance before triggering encryption across at least 10 hosts within the targeted organization. Join the discussion | AlienVault OTX General | 07/09/2026, 12:53:27 UTC Added: 07/10/2026, 07:32:34 UTC |
The Gentlemen ransomware group, which emerged in July 2025, employed a zero-day vulnerability in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint detection and response systems. During an incident investigated in early April, the group leveraged an obscure third-party driver named ktapi.sys from Kontron to bypass security protections. The sophisticated exploit chains multiple advanced techniques to navigate Windows exploit mitigations, including bypassing Supervisor Mode Access Prevention and Supervisor Mode Execution Prevention. The toolkit enables the attackers to call privileged kernel mode functions from user mode processes, ultimately terminating EDR processes including Windows Defender, ESET, Palo Alto Cortex XDR, and SentinelOne. The vulnerability had no prior public documentation and was previously absent from vulnerable driver blocklists. Join the discussion | AlienVault OTX General | 06/30/2026, 16:35:05 UTC Added: 07/01/2026, 07:21:30 UTC |
The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors. Join the discussion | AlienVault OTX General | 06/29/2026, 11:01:00 UTC Added: 06/30/2026, 06:51:30 UTC |
A large-scale malvertising campaign targeting U.S.tax form searchers has been uncovered. The attack chain begins with Google Ads, using dual commercial cloaking services to evade detection. Victims are directed to rogue ScreenConnect installers, leading to a multi-stage crypter that ultimately deploys a BYOVD (Bring Your Own Vulnerable Driver) tool. This tool, named HwAudKiller, exploits a previously undocumented Huawei audio driver to terminate antivirus and EDR processes from kernel mode. The campaign's sophistication lies in its use of commodity tools and services, combining free-tier ScreenConnect instances, off-the-shelf crypters, and a signed driver with an exploitable weakness. The attackers consistently deploy multiple remote access tools on compromised hosts for redundancy, indicating a likely pre-ransomware or initial access broker operation. Join the discussion | AlienVault OTX General | 03/19/2026, 23:58:08 UTC Added: 03/20/2026, 08:08:28 UTC |
Showing 1 to 10 of 24 results