Follow on X RSS Feed
Cybersec Sentinel
  • Home
  • News
  • Malware
  • Ransomware
  • Vulnerabilities
  • Articles
  • About
  • FAQ

BYOVD,

A collection of 2 posts
BYOVD Ransomware Attacks Now Capable of Defeating Every Major EDR Product
Ransomware

BYOVD Ransomware Attacks Now Capable of Defeating Every Major EDR Product

GroupQilin (RaaS, cybercriminal); Warlock aka Water Manaul (cybercriminal)TypeRansomware with BYOVD EDR KillerMalwaremsimg32.dll (DLL sideload loader); rwdrv.sys (kernel memory driver); hlpdrv.sys (EDR killer driver); NSecKrnl.sys (Warlock BYOVD driver); Qilin ransomware; LockBit-derived Warlock payload (.x2anylock)Score🔴 9.5 Critical. Two active RaaS groups have deployed kernel-level tooling
Apr 7, 2026 8 min read
Reynolds Ransomware Shows Why BYOVD Is the New EDR Bypass
Ransomware

Reynolds Ransomware Shows Why BYOVD Is the New EDR Bypass

Threat Group Reynolds Ransomware Group Threat Type Ransomware with integrated Bring Your Own Vulnerable Driver exploitation Exploited Vulnerabilities CVE-2025-68947 abuse of the NsecSoft NSecKrnl driver authorisation model Malware Used Reynolds Ransomware with embedded NSecKrnl.sys kernel driver Threat Score 🔴 9.1/10 High risk Last Threat Observation 11 February 2026
Feb 11, 2026 4 min read
Page 1 of 1
Cybersec Sentinel © 2026
  • Privacy Policy
Powered by Ghost