Exploring vulnerable Windows driversCisco Talos·Dec 19, 11:04 UTC · Dec 19, 2024RansomwareCVE-2022-369960
Making Vulnerable Drivers Exploitable Without HardwareThe Hacker News·May 22, 11:38 UTC · May 22, 2026Ransomware57
Hackers Exploit Windows Policy Loophole to Forge KernelThe Hacker News·Jul 12, 03:37 UTC · Jul 12, 2023Ransomware57
Why a decade-old EnCase driver still works as an EDR killerHelp Net Security·Feb 5, 00:00 UTC · Feb 5, 2026Ransomware60
ThrottleStop driver abused to terminate AV processesKaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2025RansomwareCVE-2025-777160
Delivering vulnerable signed kernel drivers remains popular among attackersHelp Net Security·Jan 13, 00:00 UTC · Jan 13, 2022Ransomware60
AmCache artifact: forensic value and a tool for data extractionKaspersky Securelist·Oct 1, 10:00 UTC · Oct 1, 2025Ransomware57
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
RobbinHood ransomware exploit GIGABYTE driver flaw to kill security softwareSecurity Affairs·Feb 8, 00:20 UTC · Feb 8, 2020RansomwareCVE-2018-1932060
BlackCat Ransomware affiliate uses signed kernel driver to evade detectionSecurity Affairs·May 23, 06:51 UTC · May 23, 2023Ransomware57
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM supportHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2026Ransomware57
AuKill tool uses BYOVD attack to disable EDR softwareSecurity Affairs·Apr 24, 21:42 UTC · Apr 24, 2023Ransomware57
Stolen certificates in two waves of ransomware and wiper attacksKaspersky Securelist·Dec 22, 17:01 UTC · Dec 22, 2022Ransomware60
BlackByte Ransomware abuses driver to bypass security solutionsSecurity Affairs·Oct 8, 16:23 UTC · Oct 8, 2022RansomwareCVE-2018-19320CVE-2019-1609860
Microsoft launches center for reporting malicious driversThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware57
Ransomware uses vulnerable, signed driver to disable endpoint securityHelp Net Security·Feb 10, 00:00 UTC · Feb 10, 2020RansomwareCVE-2008-3431CVE-2013-3956CVE-2017-15302+1 CVEs60
GodDamn Ransomware Uses PoisonX to Blind Security SoftwareSecurity Affairs·Jul 9, 18:11 UTC · Jul 9, 2026Ransomware57
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR ToolsThe Hacker News·Apr 6, 10:07 UTC · Apr 6, 2026Ransomware57
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security ToolsThe Hacker News·Feb 17, 05:50 UTC · Feb 17, 2026RansomwareCVE-2025-68947CVE-2025-6115560
Reynolds ransomware uses BYOVD to disable security before encryptionSecurity Affairs·Feb 11, 15:00 UTC · Feb 11, 2026RansomwareCVE-2025-6894760
New York fines Geico, Travelers $11 million for exposed driver’s license numbersThe Record·Nov 25, 21:28 UTC · Nov 25, 2024Ransomware57
Medusa Ransomware Uses Malicious Driver to Disable AntiThe Hacker News·Mar 22, 04:07 UTC · Mar 22, 2025Ransomware57
GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking AttackThe Hacker News·May 29, 05:25 UTC · May 29, 2024RansomwareCVE-2021-44228CVE-2023-24860CVE-2023-3601060
Medusa ransomware uses malicious Windows driver ABYSSWORKER to disable security toolsSecurity Affairs·Mar 24, 14:56 UTC · Mar 24, 2025Ransomware57
Novel News on Cuba Ransomware: Greetings From Tropical ScorpiusPalo Alto Unit 42·Jun 5, 20:16 UTC · Jun 5, 2024Ransomware57
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint DefensesThe Hacker News·Jul 10, 07:50 UTC · Jul 10, 2026Ransomware57
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD AttackThe Hacker News·Jan 24, 08:57 UTC · Jan 24, 2026RansomwareCVE-2019-1158060
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
Ransomware gangs exploit a Paragon Partition Manager BioNTdrv.sys driver zeroSecurity Affairs·Mar 1, 18:52 UTC · Mar 1, 2025Ransomware in the wildCVE-2025-0289CVE-2025-0288CVE-2025-0287+2 CVEs60
BlackByte Ransomware Abuses Vulnerable Windows Driver to Disable Security SolutionsThe Hacker News·May 29, 04:43 UTC · May 29, 2024RansomwareCVE-2019-16098CVE-2018-1932060
Abusing Windows Container Isolation Framework to avoid detection by security productsSecurity Affairs·Aug 31, 07:43 UTC · Aug 31, 2023Ransomware57
54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable SecurityThe Hacker News·Mar 20, 04:36 UTC · Mar 20, 2026Ransomware57
Signed Microsoft Drivers Used in Attacks Against BusinessesInfosecurity Magazine·Dec 14, 18:00 UTC · Dec 14, 2022Ransomware60
Hackers Exploit Paragon Partition Manager Driver Vulnerability in Ransomware AttacksThe Hacker News·Mar 3, 13:56 UTC · Mar 3, 2025RansomwareCVE-2025-0289CVE-2025-0285CVE-2025-0286+2 CVEs60
Overview of ransomware trends in 2023Kaspersky Securelist·May 10, 19:56 UTC · May 10, 2023RansomwareCVE-2022-26522CVE-2022-2652360
Kaspersky crimeware report: ransomware propagation and driver abuseKaspersky Securelist·Dec 5, 10:00 UTC · Dec 5, 2022RansomwareCVE-2022-26522CVE-2022-2652360
New Ransomware Exploits Malicious Driver to Remove Security ProtectionInfosecurity Magazine·Jul 10, 13:00 UTC · Jul 10, 2026Ransomware57