Exploring vulnerable Windows driversCisco Talos·Dec 19, 11:04 UTC · Dec 19, 2024RansomwareCVE-2022-369960
Making Vulnerable Drivers Exploitable Without HardwareThe Hacker News·May 22, 11:38 UTC · May 22, 2026Ransomware57
Hackers Exploit Windows Policy Loophole to Forge KernelThe Hacker News·Jul 12, 03:37 UTC · Jul 12, 2023Ransomware57
ThrottleStop driver abused to terminate AV processesKaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2025RansomwareCVE-2025-777160
AmCache artifact: forensic value and a tool for data extractionKaspersky Securelist·Oct 1, 10:00 UTC · Oct 1, 2025Ransomware57
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
RobbinHood ransomware exploit GIGABYTE driver flaw to kill security softwareSecurity Affairs·Feb 8, 00:20 UTC · Feb 8, 2020RansomwareCVE-2018-1932060
BlackCat Ransomware affiliate uses signed kernel driver to evade detectionSecurity Affairs·May 23, 06:51 UTC · May 23, 2023Ransomware57
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM supportHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2026Ransomware57
AuKill tool uses BYOVD attack to disable EDR softwareSecurity Affairs·Apr 24, 21:42 UTC · Apr 24, 2023Ransomware57
BlackByte Ransomware abuses driver to bypass security solutionsSecurity Affairs·Oct 8, 16:23 UTC · Oct 8, 2022RansomwareCVE-2018-19320CVE-2019-1609860
Microsoft launches center for reporting malicious driversThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware57
Ransomware uses vulnerable, signed driver to disable endpoint securityHelp Net Security·Feb 10, 00:00 UTC · Feb 10, 2020RansomwareCVE-2008-3431CVE-2013-3956CVE-2017-15302+1 CVEs60
GodDamn Ransomware Uses PoisonX to Blind Security SoftwareSecurity Affairs·Jul 9, 18:11 UTC · Jul 9, 2026Ransomware57
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR ToolsThe Hacker News·Apr 6, 10:07 UTC · Apr 6, 2026Ransomware57
New York fines Geico, Travelers $11 million for exposed driver’s license numbersThe Record·Nov 25, 21:28 UTC · Nov 25, 2024Ransomware57
Medusa Ransomware Uses Malicious Driver to Disable AntiThe Hacker News·Mar 22, 04:07 UTC · Mar 22, 2025Ransomware57
Medusa ransomware uses malicious Windows driver ABYSSWORKER to disable security toolsSecurity Affairs·Mar 24, 14:56 UTC · Mar 24, 2025Ransomware57
Novel News on Cuba Ransomware: Greetings From Tropical ScorpiusPalo Alto Unit 42·Jun 5, 20:16 UTC · Jun 5, 2024Ransomware57
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint DefensesThe Hacker News·Jul 10, 07:50 UTC · Jul 10, 2026Ransomware57
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD AttackThe Hacker News·Jan 24, 08:57 UTC · Jan 24, 2026RansomwareCVE-2019-1158060
BlackByte Ransomware Abuses Vulnerable Windows Driver to Disable Security SolutionsThe Hacker News·May 29, 04:43 UTC · May 29, 2024RansomwareCVE-2019-16098CVE-2018-1932060
Abusing Windows Container Isolation Framework to avoid detection by security productsSecurity Affairs·Aug 31, 07:43 UTC · Aug 31, 2023Ransomware57
54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable SecurityThe Hacker News·Mar 20, 04:36 UTC · Mar 20, 2026Ransomware57
Kaspersky crimeware report: ransomware propagation and driver abuseKaspersky Securelist·Dec 5, 10:00 UTC · Dec 5, 2022RansomwareCVE-2022-26522CVE-2022-2652360
New Ransomware Exploits Malicious Driver to Remove Security ProtectionInfosecurity Magazine·Jul 10, 13:00 UTC · Jul 10, 2026Ransomware57
EDR killers are now standard equipment in ransomware attacksHelp Net Security·Apr 23, 13:28 UTC · Apr 23, 2026Ransomware57
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security ProcessesThe Hacker News·Jun 23, 17:43 UTC · Jun 23, 2026Ransomware57
Ransomware Hackers Using AuKill Tool to Disable EDR Software Using BYOVD AttackThe Hacker News·Apr 28, 03:18 UTC · Apr 28, 2023Ransomware57
Ransomware Attackers Abuse Genshin Impact AntiThe Hacker News·Sep 5, 12:26 UTC · Sep 5, 2022Ransomware57
Insurer unveils policy covering drivers from connected car hacks and data leaksThe Record·Mar 27, 15:25 UTC · Mar 27, 2024Ransomware57
DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two MonthsSecurity Affairs·Jun 17, 15:55 UTC · Jun 17, 2026Ransomware57
FIN7 group advertises new EDR bypass tool on hacking forumsSecurity Affairs·Jul 18, 11:04 UTC · Jul 18, 2024Ransomware57
Friday Squid Blogging: 14-foot Giant Squid Washes Ashore in Cape TownSchneier on Security·Aug 26, 21:08 UTC · Aug 26, 2022Ransomware57
GentleKiller Framework Disables Victims' Security SoftwareInfosecurity Magazine·Jun 22, 15:00 UTC · Jun 22, 2026Ransomware57
A group linked to RansomHub operation employs EDRSecurity Affairs·Aug 15, 20:12 UTC · Aug 15, 2024Ransomware57