BYOVD Attacks Turn Signed Vulnerable Drivers into Kernel-Level Backdoors

· Original article ↗

Summary

The article examines how ransomware operators abuse signed, vulnerable Windows drivers to gain kernel-level access and disable endpoint defenses, highlighting active groups, driver-blocklist evasions, and gaps in signature enforcement.

Key points

  • ESET’s March 2026 report found 54 of nearly 90 EDR-killer tools in active use relied on BYOVD, collectively abusing 35 vulnerable drivers.
  • Attackers with local administrator access load signed vulnerable drivers to gain kernel-level privileges and disable EDR or antivirus protections.
  • The article describes BYOVD use by ransomware groups including Gentlemen, Qilin, DeadLock, and Reynolds, with drivers used to terminate security processes before encryption.
  • SilverFox reportedly uses a framework that can switch among three vulnerable signed drivers, while Qilin’s driver chain was observed in Akira and Makop intrusions.
  • Attackers reportedly created more than 2,500 TrueSight.sys variants by changing eight bytes, giving each a unique hash that could evade hash-based blocklisting.
  • A Huntress investigation found an expired, revoked driver could still load because of a trusted timestamp and a legacy cross-signing exception.

Article Details

Attack Vectors
  • BYOVD attacks load legitimate, signed but vulnerable drivers after obtaining local administrator access, then exploit them for kernel-level execution and to disable endpoint defenses.
  • Gentlemen supplies affiliates with GentleKiller, an eight-variant EDR-killing framework that uses different vulnerable or malicious drivers.
  • Silver Fox uses a framework that can switch among BootRepair.sys, EnPortv.sys, and wsftprm.sys if one driver is blocklisted.
  • Reynolds ransomware embeds a vulnerable NsecSoft NSecKrnl driver in its payload, drops it as C:\ProgramData\402.sys, and loads it to terminate security processes before encryption.
  • GodDamn attackers deployed the PoisonX driver alongside a user-mode evasion tool disguised as a Symantec product.
  • Qilin used DLL side-loading in a multi-stage chain that loaded rwdrv.sys and hlpdrv.sys to access physical memory, unregister EDR kernel callbacks, and terminate EDR drivers.
  • DeadLock used a BYOVD loader against a vulnerable Baidu Antivirus driver to terminate EDR processes and impair defenses and recovery.
  • Attackers altered eight bytes in the PE header of TrueSight.sys version 2.0.2 to produce more than 2,500 distinct, signed variants with unique hashes, according to CheckPoint.
Defensive Notes
  • Microsoft's Vulnerable Driver Blocklist denies known-bad drivers using hashes, file names and versions, and signer certificates, but the article says it is insufficient on its own.
  • CheckPoint reported that the distinct hashes and valid signatures of modified TrueSight.sys variants let them bypass the blocklist.
  • Huntress reported that an EnPortv.sys driver loaded despite an expired and revoked certificate because its signature retained a trusted pre-expiry timestamp and qualified for a legacy cross-signing exception.

MITRE ATT&CK

CVE

Threat Actors

Malware

Vendors

AvastUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.Baidu2025, Cisco Talos documented a DeadLock ransomware campaign using a BYOVD loader against a vulnerable Baidu Antivirus driver to terminate EDR processes, disable Windows Defender entirely, stop services, and impairBitdefenderBitdefender predicts BYOVD will reach a prevalence rate of 75% or more in ransomware attacks going forward.CrowdStrikeGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.ESETESET's March 2026 report traced almost 90 EDR killer tools in active use, and 54 of them lean on the same trick: Bring Your Own Vulnerable Driver (BYOVD), collectively abusing 35 distinct vulnerable drivers.KasperskyGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.MicrosoftOne variant, G11, uses PoisonX—a driver that appears to have been signed by Microsoft itself.NsecSoftIn February 2026, Reynolds ransomware emerged as a new ransomware family with a vulnerable NsecSoft NSecKrnl driver (CVE-2025-68947) embedded directly inside the ransomware payload itself, not dropped as a separate tool.Palo Alto NetworksGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.SentinelOneGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.SophosGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.SymantecUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.TrellixGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.

Products

AnyDeskhosts inside a single organization within two days, harvesting credentials with NirSoft tools, deploying AnyDesk for remote access, and clearing the way for encryption.CrowdStrike Falcon platformUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.DefenderGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.EnCasethat can swap between three signed-but-vulnerable drivers: BootRepair.sys, EnPortv.sys (notably from EnCase forensic software, the same vendor lineage flagged separately by Huntress in February 2026), andMicrosoft Defenderusing a BYOVD loader against a vulnerable Baidu Antivirus driver to terminate EDR processes, disable Windows Defender entirely, stop services, and impair recovery mechanisms.Palo Alto Cortex XDRUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.ThrottleStopThe chain loaded two vulnerable drivers: rwdrv.sys (a renamed ThrottleStop driver) and hlpdrv.sys to gain physical memory access, unregister EDR kernel callbacks, and terminate over 300 EDR drivers across virtuallyVulnerable Driver BlocklistMicrosoft's answer to BYOVD is the Vulnerable Driver Blocklist, they deny known-bad drivers by Authenticode hash, file name and version, and signer certificate.Windows54 out of 90 EDR killers actively used in the wild are BYOVD-based, abusing 35 signed drivers that Windows trusts by default.

Tools

Related Articles