#byovd — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #byovd, aggregated by home.social.
-
📢 ErrTraffic et Cruciferra : cocktail MaaS pour ClickFix et kill EDR via BYOVD
En août 2026, l'équipe Threat Response Unit (TRU) d'eSentire publie une analyse technique détaillée de campagnes observées fin juillet 2026, combinant deux services Malware-as-a-Service (MaaS) : ErrTraffic et Cruciferra. Les victimes atterrissent sur des sites WordPress compromis…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-22-errtraffic-et-cruciferra-cocktail-maas-pour-clickfix-et-kill-edr-via-byovd/
🌐 source : https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
🟢 vérification factuelle haute
#BYOVD #ClickFix #Cyberveille -
📢 UAT-10147 déploie SPECTRE : implant multiplateforme avec rootkit Linux et capacités BYOVD
Cet article constitue une analyse technique approfondie des outils et tactiques de UAT-10147, un acteur d'intrusion sinophone hautement capable ciblant des serveurs IIS et Linux exposés sur Internet. L'article fait suite à une précédente publication Talos documentant…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-20-uat-10147-deploie-spectre-implant-multiplateforme-avec-rootkit-linux-et-capacites-byovd/
🌐 source : https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/
🟢 vérification factuelle haute
#BYOVD #SPECTRE #Cyberveille -
Cato CTRL details a new SilverFox ValleyRAT campaign in Japan using three BYOVD drivers and DLL sideloading to kill security tools.
#SilverFox #ValleyRAT #BYOVD #Winos40 #DLLSideloading #Malware #ThreatIntel #Cybersecurity
-
Proofpoint details the Cruciferra crypter service that cloaks RATs and infostealers using BYOVD EDR tampering and 90+ custom encryption routines.
#Cruciferra #Crypter #MaaS #BYOVD #ProcessGhosting #Infostealer #RAT #Proofpoint
-
Proofpoint details the Cruciferra crypter service that cloaks RATs and infostealers using BYOVD EDR tampering and 90+ custom encryption routines.
#Cruciferra #Crypter #MaaS #BYOVD #ProcessGhosting #Infostealer #RAT #Proofpoint
-
Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco
Proofpoint svela Cruciferra, servizio di crypter venduto su forum underground che combina BYOVD, syscall indiretti e una variante di Process Ghosting per proteggere AsyncRAT, Agent Tesla, Remcos e altri RAT usati da gruppi come TA4922. -
Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco
Proofpoint svela Cruciferra, servizio di crypter venduto su forum underground che combina BYOVD, syscall indiretti e una variante di Process Ghosting per proteggere AsyncRAT, Agent Tesla, Remcos e altri RAT usati da gruppi come TA4922. -
Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco
Proofpoint svela Cruciferra, servizio di crypter venduto su forum underground che combina BYOVD, syscall indiretti e una variante di Process Ghosting per proteggere AsyncRAT, Agent Tesla, Remcos e altri RAT usati da gruppi come TA4922. -
Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco
Proofpoint svela Cruciferra, servizio di crypter venduto su forum underground che combina BYOVD, syscall indiretti e una variante di Process Ghosting per proteggere AsyncRAT, Agent Tesla, Remcos e altri RAT usati da gruppi come TA4922. -
Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco
Proofpoint svela Cruciferra, servizio di crypter venduto su forum underground che combina BYOVD, syscall indiretti e una variante di Process Ghosting per proteggere AsyncRAT, Agent Tesla, Remcos e altri RAT usati da gruppi come TA4922. -
Discover how the sophisticated Cruciferra crypter service employs BYOVD and Process Ghosting to conceal malware and evade detection across enterprise networks.
#Cruciferra #Crypter #BYOVD #ProcessGhosting #MalwareEvasion #InfoSec
https://meterpreter.org/cruciferra-crypter-service/?utm_source=mastodon&utm_medium=jetpack_social
-
Discover how the sophisticated Cruciferra crypter service employs BYOVD and Process Ghosting to conceal malware and evade detection across enterprise networks.
#Cruciferra #Crypter #BYOVD #ProcessGhosting #MalwareEvasion #InfoSec
https://meterpreter.org/cruciferra-crypter-service/?utm_source=mastodon&utm_medium=jetpack_social
-
GodDamn ransomware is the latest Beast ransomware rebrand from Hyadina. It uses a Microsoft-signed malicious kernel driver, PoisonX, to disable EDR.
-
GodDamn ransomware is the latest Beast ransomware rebrand from Hyadina. It uses a Microsoft-signed malicious kernel driver, PoisonX, to disable EDR.
-
Discover how The Gentlemen ransomware utilized a ktapi.sys zero-day BYOVD attack to bypass kernel defenses and disable EDR systems in seconds.
#TheGentlemen #Ransomware #ZeroDay #BYOVD #CyberSecurity #Expel
https://meterpreter.org/gentlemen-ransomware-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
-
Discover how The Gentlemen ransomware utilized a ktapi.sys zero-day BYOVD attack to bypass kernel defenses and disable EDR systems in seconds.
#TheGentlemen #Ransomware #ZeroDay #BYOVD #CyberSecurity #Expel
https://meterpreter.org/gentlemen-ransomware-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
-
GentleKiller Framework: How Gentlemen Ransomware Disables Victims’ Security Software - https://www.redpacketsecurity.com/gentlekiller-framework-disables-victims-security-software/
-
GentleKiller Framework: How Gentlemen Ransomware Disables Victims’ Security Software - https://www.redpacketsecurity.com/gentlekiller-framework-disables-victims-security-software/
-
GentleKiller Framework: How Gentlemen Ransomware Disables Victims’ Security Software - https://www.redpacketsecurity.com/gentlekiller-framework-disables-victims-security-software/
-
GentleKiller Framework: How Gentlemen Ransomware Disables Victims’ Security Software - https://www.redpacketsecurity.com/gentlekiller-framework-disables-victims-security-software/
-
GentleKiller Framework: How Gentlemen Ransomware Disables Victims’ Security Software - https://www.redpacketsecurity.com/gentlekiller-framework-disables-victims-security-software/
-
Ransomware Gang Disables Security Software with GentleKiller Framework
Meet GentleKiller, a sneaky framework that helps ransomware gangs disable security software by targeting over 400 processes across 48 security products at the kernel level, allowing them to run unchecked. This sinister tool uses a "bring your own vulnerable driver" technique to terminate protections and clear the way for…
#Ransomware #Gentlekiller #Byovd #EndpointDetectionAndResponse #EdrKiller
-
Ransomware Gang Disables Security Software with GentleKiller Framework
Meet GentleKiller, a sneaky framework that helps ransomware gangs disable security software by targeting over 400 processes across 48 security products at the kernel level, allowing them to run unchecked. This sinister tool uses a "bring your own vulnerable driver" technique to terminate protections and clear the way for…
#Ransomware #Gentlekiller #Byovd #EndpointDetectionAndResponse #EdrKiller
-
Ransomware Gang Disables Security Software with GentleKiller Framework
Meet GentleKiller, a sneaky framework that helps ransomware gangs disable security software by targeting over 400 processes across 48 security products at the kernel level, allowing them to run unchecked. This sinister tool uses a "bring your own vulnerable driver" technique to terminate protections and clear the way for…
#Ransomware #Gentlekiller #Byovd #EndpointDetectionAndResponse #EdrKiller
-
Ransomware Gang Disables Security Software with GentleKiller Framework
Meet GentleKiller, a sneaky framework that helps ransomware gangs disable security software by targeting over 400 processes across 48 security products at the kernel level, allowing them to run unchecked. This sinister tool uses a "bring your own vulnerable driver" technique to terminate protections and clear the way for…
#Ransomware #Gentlekiller #Byovd #EndpointDetectionAndResponse #EdrKiller
-
Ransomware Gang Disables Security Software with GentleKiller Framework
Meet GentleKiller, a sneaky framework that helps ransomware gangs disable security software by targeting over 400 processes across 48 security products at the kernel level, allowing them to run unchecked. This sinister tool uses a "bring your own vulnerable driver" technique to terminate protections and clear the way for…
#Ransomware #Gentlekiller #Byovd #EndpointDetectionAndResponse #EdrKiller
-
📢 Gentlemen RaaS : une suite EDR killer combinant HexKiller, ThrottleBlood et HavocKiller
📝 ## 🎯 ContexteAnalyse publiée le 20 juin 2026 par Cyber Press, basée sur des recherches d'ESET, Group-IB et PRODAFT, portant sur la suite EDR killer...
📖 cyberveille : https://cyberveille.ch/posts/2026-06-21-gentlemen-raas-une-suite-edr-killer-combinant-hexkiller-throttleblood-et-havockiller/
🌐 source : https://cyberpress.org/gentlemen-edr-killer-suite/
#BYOVD #BlackLock #Cyberveille -
📢 Gentlemen RaaS : analyse approfondie du framework EDR killer GentleKiller
📝 ## 🔍 ContextePublié le 18 juin 2026 par ESET Research (Jakub Souček), cet article présente les résultats d'une investiga...
📖 cyberveille : https://cyberveille.ch/posts/2026-06-19-gentlemen-raas-analyse-approfondie-du-framework-edr-killer-gentlekiller/
🌐 source : https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
#BYOVD #BlackLock #Cyberveille -
Exploiting Windows Drivers Without Hardware: The BYOVD Perspective
Discover how attackers can exploit Windows drivers without hardware, turning kernel-mode driver bugs into powerful tools to bypass security controls. The Atos Threat Research Center reveals a game-changing method to manipulate reachability from userland on Windows 11 23H2.
#Byovd #Windows #KernelDrivers #VulnerabilityExploitation #Windows11
-
📢 CVE-2024-12802 : exploitation active de SonicWall SSL VPN malgré le patch firmware
📝 ## 🔍 ContextePublié le 19 mai 2026 par ReliaQuest Threat Research (auteurs : Alexander Capraro et Tristan Luikey),...
📖 cyberveille : https://cyberveille.ch/posts/2026-05-21-cve-2024-12802-exploitation-active-de-sonicwall-ssl-vpn-malgre-le-patch-firmware/
🌐 source : https://reliaquest.com/blog/threat-spotlight-vpn-exploitation-when-patched-doesnt-mean-protected/
#Akira #BYOVD #Cyberveille -
📢 LOLDrivers : ajout de nouveaux drivers vulnérables IoBitUnlocker, Zemana et TfSysMon utilisés en BYOVD
📝 ## 🔍 ContexteLe 13 mars 2026, une pull request (#221) a été fusionnée dans le dépôt public **LOLDrivers** (magicsword-io),...
📖 cyberveille : https://cyberveille.ch/posts/2026-04-05-loldrivers-ajout-de-nouveaux-drivers-vulnerables-iobitunlocker-zemana-et-tfsysmon-utilises-en-byovd/
🌐 source : https://github.com/magicsword-io/LOLDrivers/pull/221
#BYOVD #IOC #Cyberveille -
📢 Rétro-ingénierie de gdrv3.sys (Gigabyte) : 13 primitives d'accès matériel exploitables en BYOVD
📝 ## 🔍 ContexteArticle de recherche publié le 02 mai 2026 sur le blog personnel d'Aaron Haymore (zonifer.dev).
📖 cyberveille : https://cyberveille.ch/posts/2026-04-05-retro-ingenierie-de-gdrv3-sys-gigabyte-13-primitives-d-acces-materiel-exploitables-en-byovd/
🌐 source : https://zonifer.dev/posts/byovd-kernel-driver-hardware-primitives.html
#BYOVD #Gigabyte #Cyberveille -
📰 Qilin Ransomware Blinds Defenses with Advanced EDR Killer, Abusing Vulnerable Drivers
🔥 Qilin ransomware deploys a sophisticated EDR killer, using a vulnerable signed driver (BYOVD) to disable over 300 security products at the kernel level. A major escalation in defense evasion tactics. #Ransomware #Qilin #EDR #CyberSecurity #BYOVD
-
📰 Qilin Ransomware Blinds Defenses with Advanced EDR Killer, Abusing Vulnerable Drivers
🔥 Qilin ransomware deploys a sophisticated EDR killer, using a vulnerable signed driver (BYOVD) to disable over 300 security products at the kernel level. A major escalation in defense evasion tactics. #Ransomware #Qilin #EDR #CyberSecurity #BYOVD
-
📢 Driver vulnérable ASTRA64.sys (EnTech Taiwan) : primitives kernel exposées sans validation
📝 ## 🔍 ContexteUne issue a été ouverte le 8 avril 2026 sur le dépôt GitHub **LOLDrivers** (magicsword-io) par le chercheur `@weezerOSINT`,...
📖 cyberveille : https://cyberveille.ch/posts/2026-04-12-driver-vulnerable-astra64-sys-entech-taiwan-primitives-kernel-exposees-sans-validation/
🌐 source : https://github.com/magicsword-io/LOLDrivers/issues/294
#ASTRA64_sys #BYOVD #Cyberveille -
BYOVD-атаки на ядро Windows через драйверы: разбираю механику, воспроизвожу, строю защиту
Вы настроили Sysmon, у вас работает EDR, события летят в SIEM. Создаётся процесс, вы видите Event ID 1. Загружается DLL, Event ID 7. Всё под контролем. А теперь кто-то загружает в систему один .sys-файл. Обычный, подписанный, из прошлого века. И события пропадают. Не потому что Sysmon упал или EDR отключили. Они работают. Просто ядро Windows больше не считает нужным им что-то рассказывать. Я залез внутрь, чтобы понять, как это устроено. Поднял WinDbg, подключился к ядру, нашёл структуры, где хранятся callback'и мониторинга. Обнулил их, повторив технику руткита Lazarus. Sysmon на месте, PID живой, но лог пустой. Меня зовут Роман Мгоев, я специалист по анализу киберугроз в Альфа-Банке, в статье пройду этот путь целиком: начиная с архитектуры колец защиты Windows, byte-патчей в памяти ядра и разбора FudModule от Lazarus обеих версий, до свежих техник zerosalarium и разбора публичных тулкитов, а в конце поделюсь семью направлениями детектирования с готовыми правилами для SIEM. Отдельный блок — про аудит драйверов, которых ещё нет ни в одной базе.
https://habr.com/ru/companies/alfa/articles/1011302/
#BYOVD #EDR #Windows_kernel #Sysmon #SIEM #Lazarus #ransomware #reverse_engineering #SOC #detection_engineering
-
BYOVD-атаки на ядро Windows через драйверы: разбираю механику, воспроизвожу, строю защиту
Вы настроили Sysmon, у вас работает EDR, события летят в SIEM. Создаётся процесс, вы видите Event ID 1. Загружается DLL, Event ID 7. Всё под контролем. А теперь кто-то загружает в систему один .sys-файл. Обычный, подписанный, из прошлого века. И события пропадают. Не потому что Sysmon упал или EDR отключили. Они работают. Просто ядро Windows больше не считает нужным им что-то рассказывать. Я залез внутрь, чтобы понять, как это устроено. Поднял WinDbg, подключился к ядру, нашёл структуры, где хранятся callback'и мониторинга. Обнулил их, повторив технику руткита Lazarus. Sysmon на месте, PID живой, но лог пустой. Меня зовут Роман Мгоев, я специалист по анализу киберугроз в Альфа-Банке, в статье пройду этот путь целиком: начиная с архитектуры колец защиты Windows, byte-патчей в памяти ядра и разбора FudModule от Lazarus обеих версий, до свежих техник zerosalarium и разбора публичных тулкитов, а в конце поделюсь семью направлениями детектирования с готовыми правилами для SIEM. Отдельный блок — про аудит драйверов, которых ещё нет ни в одной базе.
https://habr.com/ru/companies/alfa/articles/1011302/
#BYOVD #EDR #Windows_kernel #Sysmon #SIEM #Lazarus #ransomware #reverse_engineering #SOC #detection_engineering
-
BYOVD-атаки на ядро Windows через драйверы: разбираю механику, воспроизвожу, строю защиту
Вы настроили Sysmon, у вас работает EDR, события летят в SIEM. Создаётся процесс, вы видите Event ID 1. Загружается DLL, Event ID 7. Всё под контролем. А теперь кто-то загружает в систему один .sys-файл. Обычный, подписанный, из прошлого века. И события пропадают. Не потому что Sysmon упал или EDR отключили. Они работают. Просто ядро Windows больше не считает нужным им что-то рассказывать. Я залез внутрь, чтобы понять, как это устроено. Поднял WinDbg, подключился к ядру, нашёл структуры, где хранятся callback'и мониторинга. Обнулил их, повторив технику руткита Lazarus. Sysmon на месте, PID живой, но лог пустой. Меня зовут Роман Мгоев, я специалист по анализу киберугроз в Альфа-Банке, в статье пройду этот путь целиком: начиная с архитектуры колец защиты Windows, byte-патчей в памяти ядра и разбора FudModule от Lazarus обеих версий, до свежих техник zerosalarium и разбора публичных тулкитов, а в конце поделюсь семью направлениями детектирования с готовыми правилами для SIEM. Отдельный блок — про аудит драйверов, которых ещё нет ни в одной базе.
https://habr.com/ru/companies/alfa/articles/1011302/
#BYOVD #EDR #Windows_kernel #Sysmon #SIEM #Lazarus #ransomware #reverse_engineering #SOC #detection_engineering
-
📰 New 'Osiris' Ransomware Borrows TTPs from Medusa and Inc Gangs, Uses Signed Driver to Kill AV
New Osiris ransomware borrows TTPs from Medusa & Inc gangs. 🐍 It uses a custom-signed driver ('Poortry') to kill EDR/AV before encrypting files. Also uses Rclone for data theft. #Ransomware #Osiris #BYOVD #ThreatIntel
-
DeadLock ransomware now uses a new BYOVD loader exploiting Baidu driver CVE-2024-51324 to terminate EDR processes at the kernel level. Pre-encryption PowerShell scripting disables defenses and wipes shadow copies before deploying custom time-based encryption.
https://www.technadu.com/deadlock-ransomware-uses-new-byovd-loader-exploiting-driver-vulnerability-to-disable-edr/615498/#Cybersecurity #Ransomware #BYOVD #DeadLock #EDR #ThreatIntel
-
DeadLock ransomware now uses a new BYOVD loader exploiting Baidu driver CVE-2024-51324 to terminate EDR processes at the kernel level. Pre-encryption PowerShell scripting disables defenses and wipes shadow copies before deploying custom time-based encryption.
https://www.technadu.com/deadlock-ransomware-uses-new-byovd-loader-exploiting-driver-vulnerability-to-disable-edr/615498/#Cybersecurity #Ransomware #BYOVD #DeadLock #EDR #ThreatIntel
-
DeadLock ransomware now uses a new BYOVD loader exploiting Baidu driver CVE-2024-51324 to terminate EDR processes at the kernel level. Pre-encryption PowerShell scripting disables defenses and wipes shadow copies before deploying custom time-based encryption.
https://www.technadu.com/deadlock-ransomware-uses-new-byovd-loader-exploiting-driver-vulnerability-to-disable-edr/615498/#Cybersecurity #Ransomware #BYOVD #DeadLock #EDR #ThreatIntel
-
10 популярных техник обхода EDR
Алексей Баландин, Security Vision На сегодняшний день невозможно представить защиту конечных точек без системы EDR, которая, в отличие от устаревшего антивируса, основана в первую очередь на поведенческом анализе происходящих в системе событий. Потребность в этой системе резко возросла за последние 10 лет в связи с тем, что угрозы совершенствуются из года в год. Давно стало очевидно, что эффективно противостоять атакующим можно не столько за счет статического анализа кода, сигнатурного метода, сколько за счет изучения, анализа и блокировки их поведенческих паттернов, используемых тактик, техник и процедур. Этим и занимается класс продуктов EDR и активно развивается за счет постоянного пополнения базы знаний о новых методах атак. Обратной стороной медали является то, что атакующие не стоят на месте и разрабатывают все новые способы обхода и противодействия EDR. Далее рассмотрим техники обхода EDR, которые были наиболее популярны у атакующих за последние 5 лет.
https://habr.com/ru/companies/securityvison/articles/973172/
-
10 популярных техник обхода EDR
Алексей Баландин, Security Vision На сегодняшний день невозможно представить защиту конечных точек без системы EDR, которая, в отличие от устаревшего антивируса, основана в первую очередь на поведенческом анализе происходящих в системе событий. Потребность в этой системе резко возросла за последние 10 лет в связи с тем, что угрозы совершенствуются из года в год. Давно стало очевидно, что эффективно противостоять атакующим можно не столько за счет статического анализа кода, сигнатурного метода, сколько за счет изучения, анализа и блокировки их поведенческих паттернов, используемых тактик, техник и процедур. Этим и занимается класс продуктов EDR и активно развивается за счет постоянного пополнения базы знаний о новых методах атак. Обратной стороной медали является то, что атакующие не стоят на месте и разрабатывают все новые способы обхода и противодействия EDR. Далее рассмотрим техники обхода EDR, которые были наиболее популярны у атакующих за последние 5 лет.
https://habr.com/ru/companies/securityvison/articles/973172/
-
10 популярных техник обхода EDR
Алексей Баландин, Security Vision На сегодняшний день невозможно представить защиту конечных точек без системы EDR, которая, в отличие от устаревшего антивируса, основана в первую очередь на поведенческом анализе происходящих в системе событий. Потребность в этой системе резко возросла за последние 10 лет в связи с тем, что угрозы совершенствуются из года в год. Давно стало очевидно, что эффективно противостоять атакующим можно не столько за счет статического анализа кода, сигнатурного метода, сколько за счет изучения, анализа и блокировки их поведенческих паттернов, используемых тактик, техник и процедур. Этим и занимается класс продуктов EDR и активно развивается за счет постоянного пополнения базы знаний о новых методах атак. Обратной стороной медали является то, что атакующие не стоят на месте и разрабатывают все новые способы обхода и противодействия EDR. Далее рассмотрим техники обхода EDR, которые были наиболее популярны у атакующих за последние 5 лет.
https://habr.com/ru/companies/securityvison/articles/973172/
-
[Перевод] Техники обхода систем обнаружения: маскировка путей и BYOVD
Вакансии по пентесту всё чаще требуют не только понимания принципов работы ключевых СЗИ (WAF, EDR, NAC), но и практических навыков их обхода. То же самое касается EDR/AV. В реальных отчётах о кибератаках также регулярно упоминается, как злоумышленники обходят средства защиты и остаются незамеченными. Предлагаем рассмотреть пару приемов таких обходов и проверить, готовы ли ваши системы защиты к подобным вызовам.
https://habr.com/ru/companies/cloud4y/articles/962456/
#информационная_безопасность #edr #системы_защиты #мониторинг #маскировка_путей #byovd #символические_ссылки
-
[Перевод] Техники обхода систем обнаружения: маскировка путей и BYOVD
Вакансии по пентесту всё чаще требуют не только понимания принципов работы ключевых СЗИ (WAF, EDR, NAC), но и практических навыков их обхода. То же самое касается EDR/AV. В реальных отчётах о кибератаках также регулярно упоминается, как злоумышленники обходят средства защиты и остаются незамеченными. Предлагаем рассмотреть пару приемов таких обходов и проверить, готовы ли ваши системы защиты к подобным вызовам.
https://habr.com/ru/companies/cloud4y/articles/962456/
#информационная_безопасность #edr #системы_защиты #мониторинг #маскировка_путей #byovd #символические_ссылки
-
🚨 EDR-Redir exploit uses Windows’ Bind & Cloud Filter drivers to redirect or isolate EDR folders from user mode - no kernel privileges required.
Demoed by TwoSevenOneT, it breaks Elastic Defend, Sophos, and even disables Defender via CFAPI corruption.
Minifilter abuse is becoming the new weak link in EDR design.
💬 Thoughts on how vendors should adapt?
Follow TechNadu for continuous#ThreatResearch and #EDREvasion updates.
#InfoSec #CyberSecurity #EDR #BYOVD #WindowsSecurity #MalwareAnalysis #RedTeam -
🚨 EDR-Redir exploit uses Windows’ Bind & Cloud Filter drivers to redirect or isolate EDR folders from user mode - no kernel privileges required.
Demoed by TwoSevenOneT, it breaks Elastic Defend, Sophos, and even disables Defender via CFAPI corruption.
Minifilter abuse is becoming the new weak link in EDR design.
💬 Thoughts on how vendors should adapt?
Follow TechNadu for continuous#ThreatResearch and #EDREvasion updates.
#InfoSec #CyberSecurity #EDR #BYOVD #WindowsSecurity #MalwareAnalysis #RedTeam -
⚠️ AV Killer malware disables most antivirus tools using BYOVD attack via ThrottleStop.sys (TechPowerUp driver)
- Exploits CVE-2025-7771
- Kills AVs: CrowdStrike, BitDefender, Defender, Kaspersky
- Enables ransomware like MedusaLocker
- Active in Russia, Brazil, and Ukraine🧩 SecureList | Full write-up: ⬇️
https://www.technadu.com/novel-av-killer-malware-exploits-legitimate-driver-throttlestop-sys-targets-all-major-antivirus-solutions/605482/#BYOVD #CVE20257771 #AVKiller #Malware #MedusaLocker #Infosec #ThreatIntel
-
⚠️ AV Killer malware disables most antivirus tools using BYOVD attack via ThrottleStop.sys (TechPowerUp driver)
- Exploits CVE-2025-7771
- Kills AVs: CrowdStrike, BitDefender, Defender, Kaspersky
- Enables ransomware like MedusaLocker
- Active in Russia, Brazil, and Ukraine🧩 SecureList | Full write-up: ⬇️
https://www.technadu.com/novel-av-killer-malware-exploits-legitimate-driver-throttlestop-sys-targets-all-major-antivirus-solutions/605482/#BYOVD #CVE20257771 #AVKiller #Malware #MedusaLocker #Infosec #ThreatIntel
-
State of ransomware in 2025 – Source: securelist.com https://ciso2ciso.com/state-of-ransomware-in-2025-source-securelist-com/ #rssfeedpostgeneratorecho #APT(Targetedattacks) #Crossplatformmalware #CyberSecurityNews #MalwareStatistics #Financialthreats #MicrosoftWindows #Targetedattacks #DataEncryption #securelistcom #Publications #ransomware #Lockbit #BYOVD #RaaS #APT #LLM #AI
-
State of ransomware in 2025 – Source: securelist.com https://ciso2ciso.com/state-of-ransomware-in-2025-source-securelist-com/ #rssfeedpostgeneratorecho #APT(Targetedattacks) #Crossplatformmalware #CyberSecurityNews #MalwareStatistics #Financialthreats #MicrosoftWindows #Targetedattacks #DataEncryption #securelistcom #Publications #ransomware #Lockbit #BYOVD #RaaS #APT #LLM #AI
-
State of ransomware in 2025 – Source: securelist.com https://ciso2ciso.com/state-of-ransomware-in-2025-source-securelist-com/ #rssfeedpostgeneratorecho #APT(Targetedattacks) #Crossplatformmalware #CyberSecurityNews #MalwareStatistics #Financialthreats #MicrosoftWindows #Targetedattacks #DataEncryption #securelistcom #Publications #ransomware #Lockbit #BYOVD #RaaS #APT #LLM #AI
-
An APT group exploited ESET flaw to execute malware – Source: securityaffairs.com https://ciso2ciso.com/an-apt-group-exploited-eset-flaw-to-execute-malware-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #ToddyCatAPT #Security #hacking #BYOVD #eset #APT
-
An APT group exploited ESET flaw to execute malware – Source: securityaffairs.com https://ciso2ciso.com/an-apt-group-exploited-eset-flaw-to-execute-malware-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #ToddyCatAPT #Security #hacking #BYOVD #eset #APT
-
An APT group exploited ESET flaw to execute malware – Source: securityaffairs.com https://ciso2ciso.com/an-apt-group-exploited-eset-flaw-to-execute-malware-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #ToddyCatAPT #Security #hacking #BYOVD #eset #APT
-
How ToddyCat tried to hide behind AV software – Source: securelist.com https://ciso2ciso.com/how-toddycat-tried-to-hide-behind-av-software-source-securelist-com/ #Vulnerabilitiesandexploits #AntivirusVulnerabilities #rssfeedpostgeneratorecho #zerodayvulnerabilities #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Defenseevasion #Windowsmalware #securelistcom #Encryption #Incidents #ToddyCat #Drivers #Malware #Trojan #BYOVD #APT #CVE #DLL
-
How ToddyCat tried to hide behind AV software – Source: securelist.com https://ciso2ciso.com/how-toddycat-tried-to-hide-behind-av-software-source-securelist-com/ #Vulnerabilitiesandexploits #AntivirusVulnerabilities #rssfeedpostgeneratorecho #zerodayvulnerabilities #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Defenseevasion #Windowsmalware #securelistcom #Encryption #Incidents #ToddyCat #Drivers #Malware #Trojan #BYOVD #APT #CVE #DLL
-
How ToddyCat tried to hide behind AV software – Source: securelist.com https://ciso2ciso.com/how-toddycat-tried-to-hide-behind-av-software-source-securelist-com/ #Vulnerabilitiesandexploits #AntivirusVulnerabilities #rssfeedpostgeneratorecho #zerodayvulnerabilities #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Defenseevasion #Windowsmalware #securelistcom #Encryption #Incidents #ToddyCat #Drivers #Malware #Trojan #BYOVD #APT #CVE #DLL