Vendor
Avast
- First Reported
- Aug 19, 2026
- Latest Reported
- Aug 19, 2026
Reported Context (1)
- Upon execution, it dropped the driver as C:\ProgramData\402.sys, loaded it, and used it to terminate processes from CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec, and Avast before encryption began. BYOVD Attacks Turn Signed Vulnerable Drivers into Kernel-Level Backdoors
CVE (2)
Malware (9)
Threat Actors (5)
MITRE ATT&CK (4)
Vendors (12)
Products (9)
Tools (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.