Exploring vulnerable Windows driversCisco Talos·Dec 19, 11:04 UTC · Dec 19, 2024RansomwareCVE-2022-369960
Why a decade-old EnCase driver still works as an EDR killerHelp Net Security·Feb 5, 00:00 UTC · Feb 5, 2026Ransomware60
ThrottleStop driver abused to terminate AV processesKaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2025RansomwareCVE-2025-777160
Delivering vulnerable signed kernel drivers remains popular among attackersHelp Net Security·Jan 13, 00:00 UTC · Jan 13, 2022Ransomware60
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
RobbinHood ransomware exploit GIGABYTE driver flaw to kill security softwareSecurity Affairs·Feb 8, 00:20 UTC · Feb 8, 2020RansomwareCVE-2018-1932060
Stolen certificates in two waves of ransomware and wiper attacksKaspersky Securelist·Dec 22, 17:01 UTC · Dec 22, 2022Ransomware60
BlackByte Ransomware abuses driver to bypass security solutionsSecurity Affairs·Oct 8, 16:23 UTC · Oct 8, 2022RansomwareCVE-2018-19320CVE-2019-1609860
Ransomware uses vulnerable, signed driver to disable endpoint securityHelp Net Security·Feb 10, 00:00 UTC · Feb 10, 2020RansomwareCVE-2008-3431CVE-2013-3956CVE-2017-15302+1 CVEs60
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security ToolsThe Hacker News·Feb 17, 05:50 UTC · Feb 17, 2026RansomwareCVE-2025-68947CVE-2025-6115560
Reynolds ransomware uses BYOVD to disable security before encryptionSecurity Affairs·Feb 11, 15:00 UTC · Feb 11, 2026RansomwareCVE-2025-6894760
GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking AttackThe Hacker News·May 29, 05:25 UTC · May 29, 2024RansomwareCVE-2021-44228CVE-2023-24860CVE-2023-3601060
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD AttackThe Hacker News·Jan 24, 08:57 UTC · Jan 24, 2026RansomwareCVE-2019-1158060
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
Ransomware gangs exploit a Paragon Partition Manager BioNTdrv.sys driver zeroSecurity Affairs·Mar 1, 18:52 UTC · Mar 1, 2025Ransomware in the wildCVE-2025-0289CVE-2025-0288CVE-2025-0287+2 CVEs60
BlackByte Ransomware Abuses Vulnerable Windows Driver to Disable Security SolutionsThe Hacker News·May 29, 04:43 UTC · May 29, 2024RansomwareCVE-2019-16098CVE-2018-1932060
Signed Microsoft Drivers Used in Attacks Against BusinessesInfosecurity Magazine·Dec 14, 18:00 UTC · Dec 14, 2022Ransomware60
Hackers Exploit Paragon Partition Manager Driver Vulnerability in Ransomware AttacksThe Hacker News·Mar 3, 13:56 UTC · Mar 3, 2025RansomwareCVE-2025-0289CVE-2025-0285CVE-2025-0286+2 CVEs60
Overview of ransomware trends in 2023Kaspersky Securelist·May 10, 19:56 UTC · May 10, 2023RansomwareCVE-2022-26522CVE-2022-2652360
Kaspersky crimeware report: ransomware propagation and driver abuseKaspersky Securelist·Dec 5, 10:00 UTC · Dec 5, 2022RansomwareCVE-2022-26522CVE-2022-2652360
The Gentlemen RaaS: rapid growth and a new ransomware variantKaspersky Securelist·Jun 30, 10:06 UTC · Jun 30, 2026Ransomware160
H1 2023: Ransomware's Pivot to Linux and Vulnerable DriversRecorded Future·Jun 29, 00:00 UTC · Jun 29, 2026Ransomware60
Windows CLFS and five exploits used by ransomware operatorsKaspersky Securelist·Dec 21, 09:53 UTC · Dec 21, 2023RansomwareCVE-2023-28252CVE-2022-24521CVE-2022-37969+1 CVEs60
Chinese-speaking hackers exploited ESXi zeroSecurity Affairs·Jan 9, 00:06 UTC · Jan 9, 2026Ransomware in the wildCVE-2025-22226CVE-2025-22224CVE-2025-2222560
Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVDSecurity Affairs·Oct 27, 10:45 UTC · Oct 27, 2025Ransomware60
SonicWall Investigating Potential SSL VPN ZeroThe Hacker News·Aug 7, 05:27 UTC · Aug 7, 2025Ransomware in the wild60
CosmicBeetle Deploys Custom ScRansom Ransomware, Partnering with RansomHubThe Hacker News·Sep 11, 06:02 UTC · Sep 11, 2024RansomwareCVE-2017-0144CVE-2020-1472CVE-2021-42278+3 CVEs160
BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack WaveThe Hacker News·Aug 29, 15:41 UTC · Aug 29, 2024RansomwareCVE-2024-3708560
CVE-2025-22225 in VMware ESXi now used in active ransomware attacksSecurity Affairs·Feb 4, 22:02 UTC · Feb 4, 2026Ransomware in the wildCVE-2025-22225CVE-2025-22226CVE-2025-2222460
⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-21590CVE-2025-24983CVE-2025-24984+27 CVEs160
BYOVD Attacks Exploit ZeroInfosecurity Magazine·Mar 3, 09:35 UTC · Mar 3, 2025RansomwareCVE-2025-0289CVE-2025-0288CVE-2025-0287+2 CVEs60
BlackByte Ransomware group targets recently patched VMware ESXi flaw CVE-2024Security Affairs·Aug 28, 14:39 UTC · Aug 28, 2024RansomwareCVE-2024-3708560
Cybercriminals mask malicious communications through Microsoft Teams relaysHelp Net Security·Jun 16, 00:00 UTC · Jun 16, 2026RansomwareCVE-2023-52271CVE-2025-61155CVE-2025-1055160
Reviewing the trends in ransomware attacks in 2026Kaspersky Securelist·May 12, 07:00 UTC · May 12, 2026Ransomware60
China-Linked Hackers Exploit VMware ESXi ZeroThe Hacker News·Jan 12, 16:25 UTC · Jan 12, 2026Ransomware in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
⚡ Weekly Recap: BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & MoreThe Hacker News·Aug 12, 04:40 UTC · Aug 12, 2025Ransomware in the wildCVE-2025-54948CVE-2025-54987CVE-2025-8088+30 CVEs60
Third Parties and Machine Credentials: The Silent Drivers Behind 2025's Worst BreachesThe Hacker News·May 6, 15:39 UTC · May 6, 2025Ransomware60