Threats Tagged 'cve-2024-51324'
View all threats tagged with 'cve-2024-51324'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-51324'
Click on any threat for detailed analysis and mitigation recommendations
0 The DeadLock ransomware campaign employs a new Bring Your Own Vulnerable Driver (BYOVD) loader exploiting CVE-2024-51324, a vulnerability in Baidu Antivirus driver, to evade endpoint detection and response (EDR) tools. Attackers use PowerShell scripts to bypass User Account Control (UAC), disable Windows Defender, terminate security services, and delete volume shadow copies, facilitating ransomware deployment. DeadLock ransomware targets Windows systems with a custom stream cipher encryption using time-based cryptographic keys, employing advanced techniques such as recursive directory traversal, memory-mapped file I/O, and multi-threaded processing. Initial access is gained through compromised accounts, followed by system registry modifications, remote access establishment, reconnaissance, lateral movement, and defense impairment. Although no known exploits are currently in the wild, the sophisticated use of BYOVD and defense evasion techniques poses a significant threat to organizations. The attack complexity and multi-stage process highlight the need for targeted mitigation strategies. This threat is particularly relevant to European organizations using Baidu Antivirus or similar vulnerable drivers and those with Windows-based infrastructure. The suggested severity is high due to the potential for widespread impact, ease of defense evasion, and the ransomware’s destructive capabilities. Join the discussion | AlienVault OTX General | 12/10/2025, 09:43:19 UTC Added: 12/10/2025, 10:05:28 UTC |
Showing 1 to 1 of 1 result