logo

Black Basta Ransomware Actors Embeds BYOVD Defense Evasion Component with Ransomware Payload Itself

ID: edba31e9-f8a8-5e24-9e3d-1483c2318037

STIX ID: report--edba31e9-f8a8-5e24-9e3d-1483c2318037

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Black Basta has shifted tactics by embedding a vulnerable signed kernel driver (NsecSoft NSecKrnl, CVE-2025-68947) inside its ransomware payload to obtain kernel privileges, kill security/EDR processes (e.g., SophosHealth.exe, MsMpEng.exe), and encrypt files with a .locked extension; Symantec attributes the behavior to activity linked with the Cardinal cybercrime group and notes prior side-loaded loaders—organizations should consult Symantec’s protection bulletin for IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.