BYOVD Attacks Turn Signed Vulnerable Drivers into Kernel-Level Backdoors

Summary
The article examines how ransomware operators abuse signed, vulnerable Windows drivers to gain kernel-level access and disable endpoint defenses, highlighting active groups, driver-blocklist evasions, and gaps in signature enforcement.
Key points
- ESET’s March 2026 report found 54 of nearly 90 EDR-killer tools in active use relied on BYOVD, collectively abusing 35 vulnerable drivers.
- Attackers with local administrator access load signed vulnerable drivers to gain kernel-level privileges and disable EDR or antivirus protections.
- The article describes BYOVD use by ransomware groups including Gentlemen, Qilin, DeadLock, and Reynolds, with drivers used to terminate security processes before encryption.
- SilverFox reportedly uses a framework that can switch among three vulnerable signed drivers, while Qilin’s driver chain was observed in Akira and Makop intrusions.
- Attackers reportedly created more than 2,500 TrueSight.sys variants by changing eight bytes, giving each a unique hash that could evade hash-based blocklisting.
- A Huntress investigation found an expired, revoked driver could still load because of a trusted timestamp and a legacy cross-signing exception.
Article Details
- Attack Vectors
- BYOVD attacks load legitimate, signed but vulnerable drivers after obtaining local administrator access, then exploit them for kernel-level execution and to disable endpoint defenses.
- Gentlemen supplies affiliates with GentleKiller, an eight-variant EDR-killing framework that uses different vulnerable or malicious drivers.
- Silver Fox uses a framework that can switch among BootRepair.sys, EnPortv.sys, and wsftprm.sys if one driver is blocklisted.
- Reynolds ransomware embeds a vulnerable NsecSoft NSecKrnl driver in its payload, drops it as C:\ProgramData\402.sys, and loads it to terminate security processes before encryption.
- GodDamn attackers deployed the PoisonX driver alongside a user-mode evasion tool disguised as a Symantec product.
- Qilin used DLL side-loading in a multi-stage chain that loaded rwdrv.sys and hlpdrv.sys to access physical memory, unregister EDR kernel callbacks, and terminate EDR drivers.
- DeadLock used a BYOVD loader against a vulnerable Baidu Antivirus driver to terminate EDR processes and impair defenses and recovery.
- Attackers altered eight bytes in the PE header of TrueSight.sys version 2.0.2 to produce more than 2,500 distinct, signed variants with unique hashes, according to CheckPoint.
- Defensive Notes
- Microsoft's Vulnerable Driver Blocklist denies known-bad drivers using hashes, file names and versions, and signer certificates, but the article says it is insufficient on its own.
- CheckPoint reported that the distinct hashes and valid signatures of modified TrueSight.sys variants let them bypass the blocklist.
- Huntress reported that an EnPortv.sys driver loaded despite an expired and revoked certificate because its signature retained a trusted pre-expiry timestamp and qualified for a legacy cross-signing exception.
MITRE ATT&CK
T1068 · Exploitation for Privilege EscalationAttackers exploit flaws in signed drivers after loading them to obtain kernel-level execution.T1219 · Remote Access ToolsGodDamn attackers deployed AnyDesk for remote access during an intrusion.T1562.001 · Disable or Modify ToolsBYOVD tools disable endpoint defenses by terminating security processes or drivers and unregistering EDR kernel callbacks.T1574.002 · DLL Side-LoadingThe article says Qilin used DLL side-loading in its multi-stage BYOVD chain.
CVE
CVE-2023-52271software, the same vendor lineage flagged separately by Huntress in February 2026), and wsftprm.sys (CVE-2023-52271) — so the operation survives if any single driver gets blocklisted.CVE-2025-68947In February 2026, Reynolds ransomware emerged as a new ransomware family with a vulnerable NsecSoft NSecKrnl driver (CVE-2025-68947) embedded directly inside the ransomware payload itself, not dropped as a separate tool.
Threat Actors
BlacksuitNamed as one of the ransomware gangs sharing EDRKillShifter.MedusaNamed as one of the ransomware gangs sharing EDRKillShifter.QilinRansomware gang named as using a multi-stage BYOVD chain and as one of the gangs sharing EDRKillShifter.Silver FoxTracked operation reported to use a framework that switches among three vulnerable drivers.The GentlemenRansomware group reported to supply affiliates with GentleKiller.
Malware
AkiraThe same driver combo was also observed in Akira and Makop intrusions.BeastIn mid-2026, Symantec's Threat Hunter Team spotted a new ransomware family called GodDamn (assessed to be a rebrand of Beast ransomware) deploying a driver called PoisonX (g11.sys).DeadLockDeadLock Ransomware (December 2025)GodDamnGodDamn Ransomware & PoisonX ( July 2026)MakopThe same driver combo was also observed in Akira and Makop intrusions.QilinA single BYOVD tool called EDRKillShifter is now shared across eight different ransomware gangs simultaneously, including Qilin, Medusa, and Blacksuit.ReynoldsReynolds Ransomware (February 2026)ValleyRATCato CTRL's July 2026 research shows Silver Fox (also tracked via its ValleyRAT/Winos 4.0 implant) moving beyond single-driver BYOVD into a reusable framework that can swap between three signed-but-vulnerable drivers:Winos 4.0Cato CTRL's July 2026 research shows Silver Fox (also tracked via its ValleyRAT/Winos 4.0 implant) moving beyond single-driver BYOVD into a reusable framework that can swap between three signed-but-vulnerable drivers:
Vendors
AvastUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.Baidu2025, Cisco Talos documented a DeadLock ransomware campaign using a BYOVD loader against a vulnerable Baidu Antivirus driver to terminate EDR processes, disable Windows Defender entirely, stop services, and impairBitdefenderBitdefender predicts BYOVD will reach a prevalence rate of 75% or more in ransomware attacks going forward.CrowdStrikeGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.ESETESET's March 2026 report traced almost 90 EDR killer tools in active use, and 54 of them lean on the same trick: Bring Your Own Vulnerable Driver (BYOVD), collectively abusing 35 distinct vulnerable drivers.KasperskyGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.MicrosoftOne variant, G11, uses PoisonX—a driver that appears to have been signed by Microsoft itself.NsecSoftIn February 2026, Reynolds ransomware emerged as a new ransomware family with a vulnerable NsecSoft NSecKrnl driver (CVE-2025-68947) embedded directly inside the ransomware payload itself, not dropped as a separate tool.Palo Alto NetworksGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.SentinelOneGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.SophosGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.SymantecUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.TrellixGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.
Products
AnyDeskhosts inside a single organization within two days, harvesting credentials with NirSoft tools, deploying AnyDesk for remote access, and clearing the way for encryption.CrowdStrike Falcon platformUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.DefenderGentleKiller targets 400 EDR processes from 48 different vendors including Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky and Trellix.EnCasethat can swap between three signed-but-vulnerable drivers: BootRepair.sys, EnPortv.sys (notably from EnCase forensic software, the same vendor lineage flagged separately by Huntress in February 2026), andMicrosoft Defenderusing a BYOVD loader against a vulnerable Baidu Antivirus driver to terminate EDR processes, disable Windows Defender entirely, stop services, and impair recovery mechanisms.Palo Alto Cortex XDRUpon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began.ThrottleStopThe chain loaded two vulnerable drivers: rwdrv.sys (a renamed ThrottleStop driver) and hlpdrv.sys to gain physical memory access, unregister EDR kernel callbacks, and terminate over 300 EDR drivers across virtuallyVulnerable Driver BlocklistMicrosoft's answer to BYOVD is the Vulnerable Driver Blocklist, they deny known-bad drivers by Authenticode hash, file name and version, and signer certificate.Windows54 out of 90 EDR killers actively used in the wild are BYOVD-based, abusing 35 signed drivers that Windows trusts by default.
Tools
EDRKillShifterA single BYOVD tool called EDRKillShifter is now shared across eight different ransomware gangs simultaneously, including Qilin, Medusa, and Blacksuit.GentleKillerThis group built an in-house framework called GentleKiller with eight variants, each impersonating a different legitimate security product and using a different vulnerable or malicious driver.NirSoftacross at least ten hosts inside a single organization within two days, harvesting credentials with NirSoft tools, deploying AnyDesk for remote access, and clearing the way for encryption.