Threats Tagged 'byovd attack'
View all threats tagged with 'byovd attack'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'byovd attack'
Click on any threat for detailed analysis and mitigation recommendations
In late August, an organization experienced a ransomware attack by the INC group affecting at least 175 endpoints. The attack timeline shows two distinct phases separated by a 17-day gap, indicating possible involvement of an initial access broker followed by a ransomware affiliate. Initial activities included scheduled tasks with randomized names and lateral movement via RDP using compromised credentials. After the pause, attackers used AnyDesk for remote access, employed Bring Your Own Vulnerable Driver (BYOVD) techniques to disable security controls, and executed ransomware using Impacket tools. Two ransom notes were found: the standard INC-README.txt and a DATALEAK_PRESS_RELEASE.txt which threatened to leak stolen data to media, employees, and partners within 48 hours to increase pressure on the victim. Join the discussion | AlienVault OTX General | 09/21/2026, 16:35:37 UTC Added: 09/22/2026, 08:18:01 UTC |
Showing 1 to 1 of 1 result