daily cyber × ai intelligence

index

tagged

[byovd]

5 editions · 5 items

July 10, 2026

  • GodDamn ransomware — assessed by Symantec's Threat Hunter Team as a rebrand of Beast — uses the PoisonX kernel driver to neutralize security software before encryption. Dark Reading notes the driver was Microsoft-signed and is being used to kill EDR in attacks against US companies, continuing the run of BYOVD abuse seen with The Gentlemen's Kontron driver last week. The Hacker News · Dark Reading · Malware & Endpoint Evasion

in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0

July 6, 2026

  • The Gentlemen ransomware exploited a zero-day in a signed Kontron driver to disable endpoint defenses via classic BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware, per Expel's analysis. Recommended mitigations include driver blocklisting, VBS, and WDAC. The group has been active this week, adding roughly 20 new victims to its leak site including EMS provider Medic Rescue and German meat giant Tönnies (Expel). · Vulnerabilities & Exploits

in The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch

June 29, 2026

  • DriverScope — an automated BYOVD hunting pipeline that scans Windows .sys drivers for dangerous imports, extracts IOCTL dispatch surfaces (Capstone), runs Speakeasy emulation, and cross-references LOLDrivers, the Microsoft blocklist, KDU and VirusTotal to surface novel vulnerable-driver candidates, with a C++ comm-header generator for runtime validation and Claude-assisted triage. (GitHub, iPurpleTeam) · New Tools & Releases

in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week