logo

Reynolds ransomware uses BYOVD to disable security before encryption

ID: 001638ce-12bc-5631-8339-7033cd2cb216

STIX ID: report--001638ce-12bc-5631-8339-7033cd2cb216

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers disclosed Reynolds ransomware, which bundles a signed but vulnerable NsecKrnl driver and exploits CVE-2025-68947 (BYOVD) to kill EDR/antivirus processes and escalate privileges before encrypting files with the ".locked" extension; the campaign included a side-loaded loader and GotoHTTP access, and the report includes IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.