August 28, 2026
- Spark RAT campaigns against Cambodia are pairing an open-source RAT with BYOVD, abusing a vulnerable OPSWAT driver to disable security tooling; lures span government notices, public-health material and real estate (The Hacker News).
· Threat Activity
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
July 15, 2026 weekly
- The Gentlemen / Qilin lineage: Unit 42 profiled The Gentlemen as a high-tempo Qilin offshoot leaning on zero-days and BYOVD; Qilin still leads 2026 by volume (708 attacks). source
· Developing Stories
in The Week AI Agents Got Weaponized From Both Ends
July 10, 2026
- GodDamn ransomware — assessed by Symantec's Threat Hunter Team as a rebrand of Beast — uses the PoisonX kernel driver to neutralize security software before encryption. Dark Reading notes the driver was Microsoft-signed and is being used to kill EDR in attacks against US companies, continuing the run of BYOVD abuse seen with The Gentlemen's Kontron driver last week. The Hacker News · Dark Reading
· Malware & Endpoint Evasion
in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
July 6, 2026
- The Gentlemen ransomware exploited a zero-day in a signed Kontron driver to disable endpoint defenses via classic BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware, per Expel's analysis. Recommended mitigations include driver blocklisting, VBS, and WDAC. The group has been active this week, adding roughly 20 new victims to its leak site including EMS provider Medic Rescue and German meat giant Tönnies (Expel).
· Vulnerabilities & Exploits
in The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch
June 29, 2026
- DriverScope — an automated BYOVD hunting pipeline that scans Windows
.sys drivers for dangerous imports, extracts IOCTL dispatch surfaces (Capstone), runs Speakeasy emulation, and cross-references LOLDrivers, the Microsoft blocklist, KDU and VirusTotal to surface novel vulnerable-driver candidates, with a C++ comm-header generator for runtime validation and Claude-assisted triage. (GitHub, iPurpleTeam)
· New Tools & Releases
in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week