Black Basta Ransomware Actors Embeds BYOVD Defense Evasion Component with Ransomware Payload Itself
ID: edba31e9-f8a8-5e24-9e3d-1483c2318037
STIX ID: report--edba31e9-f8a8-5e24-9e3d-1483c2318037
Feed Name: cybersecurityNews.com
Black Basta has shifted tactics by embedding a vulnerable signed kernel driver (NsecSoft NSecKrnl, CVE-2025-68947) inside its ransomware payload to obtain kernel privileges, kill security/EDR processes (e.g., SophosHealth.exe, MsMpEng.exe), and encrypt files with a .locked extension; Symantec attributes the behavior to activity linked with the Cardinal cybercrime group and notes prior side-loaded loaders—organizations should consult Symantec’s protection bulletin for IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
